CVE-2023-48978: Code Injection
Published Jun 23, 2025
·Updated
An issue in NCR ITM Web terminal v.4.4.0 and v.4.4.4 allows a remote attacker to execute arbitrary code via a crafted script to the IP camera URL component.
Affected Software
3 affected components
NCR Itm Web Terminal>4.4.0<=4.4.4
NCR Itm Web Terminal=4.4.0
NCR Itm Web Terminal=4.4.4
Event History
Jun 23, 2025
CVE Published
via MITRE·12:00 AM
Data Sourced
via MITRE·12:00 AM
Description
Data Sourced
via NVD·03:15 PM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2023-48978?
CVE-2023-48978 has been classified as a critical vulnerability due to its ability to allow remote code execution.
2
How do I fix CVE-2023-48978?
To fix CVE-2023-48978, you should upgrade to NCR ITM Web terminal version 4.4.5 or later.
3
Which versions of NCR ITM Web terminal are affected by CVE-2023-48978?
CVE-2023-48978 affects NCR ITM Web terminal versions 4.4.0 and 4.4.4.
4
What kind of attack does CVE-2023-48978 enable?
CVE-2023-48978 enables a remote attacker to execute arbitrary code via a crafted script.
5
Is the vulnerability CVE-2023-48978 exploitable over the internet?
Yes, CVE-2023-48978 is exploitable remotely, making it a significant threat if left unpatched.