CVE Wiki Pixee · CVE intelligence
← All CVEs

CVE-2023-47031

Critical · CVSS 9.8

NCR Terminal Handler — Improper Access Control - Privilege Escalation via SOAP API

CVSS
9.8
nvd
EPSS
0.55%
42th pct
KEV
No
Class
other
CWE-284

Description

An issue in NCR Terminal Handler v.1.5.1 allows a remote attacker to escalate privileges via a crafted POST request to the grantRolesToUsers, grantRolesToGroups, and grantRolesToOrganization SOAP API component.

Search profile — drives PoC discovery

Symbols grantRolesToUsersgrantRolesToGroupsgrantRolesToOrganization
Keywords CVE-2023-47031NCR Terminal Handlerprivilege escalationSOAP APIgrantRolesToUsersgrantRolesToGroupsgrantRolesToOrganizationNCR PoC exploit
Versions: 1.5.1

References

Status: enriched · ingested 2026-07-05T06:00:39.000Z · profiled 2026-07-05T18:30:39.000Z