GHSA-3g2c-jgm5-pwjhCriticalCVSS 9.8

An issue in NCR Terminal Handler v.1.5.1 allows a remote attacker to escalate privileges via a...

Published
June 23, 2025
Last Modified
July 5, 2026

🔗 CVE IDs covered (1)

📋 Description

An issue in NCR Terminal Handler v.1.5.1 allows a remote attacker to escalate privileges via a crafted POST request to the grantRolesToUsers, grantRolesToGroups, and grantRolesToOrganization SOAP API component.

🔗 References (5)