CVE-2023-47022
—CVSS 3.1
6.5 medium
EPSS
<1%p27
Published
()
Modified
Description
Insecure Direct Object Reference in NCR Terminal Handler v.1.5.1 allows an unprivileged user to edit the audit logs for any user and can lead to CSV injection.
- Vendors
- ncr
- Products
- terminal handler
- Weakness
- CWE-639, CWE-1236
- Vector
- CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N
In the news0 stories
No ingested article mentions this CVE yet.