CVE-2023-47295: Critical severity NCR Terminal Handler vulnerability
Published Jun 23, 2025
·Updated
A CSV injection vulnerability in NCR Terminal Handler v1.5.1 allows attackers to execute arbitrary commands via injecting a crafted payload into any text field that accepts strings.
Affected Software
2 affected components
NCR Terminal Handler
NCR Terminal Handler=1.5.1
Event History
Jun 23, 2025
CVE Published
via MITRE·12:00 AM
Data Sourced
via MITRE·12:00 AM
Description
Data Sourced
via NVD·04:15 PM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2023-47295?
CVE-2023-47295 is classified as a medium severity vulnerability.
2
How do I fix CVE-2023-47295?
To fix CVE-2023-47295, ensure that proper input validation and sanitization measures are implemented for text fields in NCR Terminal Handler.
3
What type of vulnerability is CVE-2023-47295?
CVE-2023-47295 is a CSV injection vulnerability that allows for the execution of arbitrary commands.
4
What versions of NCR Terminal Handler are affected by CVE-2023-47295?
CVE-2023-47295 affects NCR Terminal Handler version 1.5.1.
5
What is the potential impact of exploiting CVE-2023-47295?
Exploiting CVE-2023-47295 can lead to unauthorized command execution on the system where NCR Terminal Handler is used.