First published: Tue Feb 06 2024(Updated: )
Insecure Direct Object Reference in NCR Terminal Handler v.1.5.1 allows an unprivileged user to edit the audit logs for any user and can lead to CSV injection.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Ncratleos Terminal Handler | =1.5.1 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2023-47022 is considered a high severity vulnerability due to the potential for unauthorized access to modify audit logs.
To fix CVE-2023-47022, upgrade NCR Terminal Handler to the latest version that addresses this vulnerability.
CVE-2023-47022 allows unprivileged users to edit audit logs, which can lead to data manipulation and potential CSV injection.
All users of NCR Terminal Handler version 1.5.1 are affected by CVE-2023-47022.
To mitigate CVE-2023-47022, implement strict access controls and monitor audit logs for unauthorized changes.