CVE-2023-47298

Publication date

2025-06-23 00:00:00

Family

mitre

State

PUBLISHED

Description

An issue in NCR Terminal Handler 1.5.1 allows a low-level privileged authenticated attacker to query the SOAP API endpoint to obtain information about all of the users of the application including their usernames, roles, security groups and account statuses.