CSV Injection Vulnerability in NCR Terminal Handler
CVE-2023-47295

9.8CRITICAL

Key Information:

Vendor
CVE Published:
23 June 2025

What is CVE-2023-47295?

A vulnerability in NCR Terminal Handler version 1.5.1 allows an attacker to exploit a CSV injection flaw by crafting a specific payload. This vulnerability permits unauthorized execution of arbitrary commands through manipulation of text fields that accept string inputs, potentially leading to severe consequences for the system's integrity.

References

CVSS V3.1

Score:
9.8
Severity:
CRITICAL
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.
CVE-2023-47295 : CSV Injection Vulnerability in NCR Terminal Handler