← Back to CVE List

CVE-2023-47024

Published: 2024-01-20T02:15Z
Last Modified: 2024-11-21T08:29Z
Source: MITRE CVE List
License: MITRE-CVE-TOS
Cross-Site Request Forgery (CSRF) in NCR Terminal Handler v.1.5.1 leads to a one-click account takeover. This is achieved by exploiting multiple vulnerabilities, including an undisclosed function in the WSDL that has weak security controls and can accept custom content types. > MITRE Terms of Use apply – see LICENSE‑MITRE.txt