Ncr

Terminal Handler

9 vulnerabilities found.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
  • EPSS 0.04%
  • Published 23.06.2025 00:00:00
  • Last modified 26.06.2025 12:44:00

An issue in NCR Terminal Handler 1.5.1 allows a low-level privileged authenticated attacker to query the SOAP API endpoint to obtain information about all of the users of the application including their usernames, roles, security groups and account s...

  • EPSS 0.08%
  • Published 23.06.2025 00:00:00
  • Last modified 26.06.2025 12:46:49

A settings manipulation vulnerability in NCR Terminal Handler v1.5.1 allows attackers to execute arbitrary commands, including editing system security auditing configurations.

  • EPSS 0.43%
  • Published 23.06.2025 00:00:00
  • Last modified 25.06.2025 13:32:01

Password Vulnerability in NCR Terminal Handler v.1.5.1 allows a remote attacker to execute arbitrary code via a crafted script to the UserService SOAP API function.

  • EPSS 0.06%
  • Published 23.06.2025 00:00:00
  • Last modified 02.07.2025 19:10:16

An issue in NCR Terminal Handler v1.5.1 allows low-level privileged authenticated attackers to arbitrarily deactivate, lock, and delete user accounts via a crafted session cookie.

  • EPSS 0.09%
  • Published 23.06.2025 00:00:00
  • Last modified 25.06.2025 13:30:08

A CSV injection vulnerability in NCR Terminal Handler v1.5.1 allows attackers to execute arbitrary commands via injecting a crafted payload into any text field that accepts strings.

  • EPSS 0.15%
  • Published 23.06.2025 00:00:00
  • Last modified 25.06.2025 13:13:50

An issue in NCR Terminal Handler v.1.5.1 allows a remote attacker to escalate privileges via a crafted POST request to the grantRolesToUsers, grantRolesToGroups, and grantRolesToOrganization SOAP API component.

  • EPSS 0.39%
  • Published 23.06.2025 00:00:00
  • Last modified 02.07.2025 19:06:22

An issue in NCR Terminal Handler v.1.5.1 allows a remote attacker to execute arbitrary code and obtain sensitive information via a crafted POST request to the UserService component

  • EPSS 0.43%
  • Published 23.06.2025 00:00:00
  • Last modified 25.06.2025 12:50:37

An issue in NCR Terminal Handler v.1.5.1 allows a remote attacker to execute arbitrary code and obtain sensitive information via a GET request to a UserService SOAP API endpoint to validate if a user exists.

  • EPSS 0.12%
  • Published 06.02.2024 01:15:07
  • Last modified 17.06.2025 17:15:31

Insecure Direct Object Reference in NCR Terminal Handler v.1.5.1 allows an unprivileged user to edit the audit logs for any user and can lead to CSV injection.