Escalating Privileges Through CSRF Chaining
CVE-2023-47020

8.8HIGH

Key Information:

Vendor
CVE Published:
8 February 2024

What is CVE-2023-47020?

The vulnerability involves multiple Cross-Site Request Forgery (CSRF) chaining mechanisms in NCR Terminal Handler version 1.5.1, enabling attackers to execute unauthorized actions. These actions can lead to the creation of user accounts with elevated privileges by exploiting a specific function embedded in the Web Services Description Language (WSDL). This vulnerable function is inadequate in its security protocols, allowing customized content types to be accepted without proper validation, thereby exposing the system to potential privilege escalation attacks.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.

Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.

References

CVSS V3.1

Score:
8.8
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.