An issue in NCR Terminal Handler v1.5.1 allows low-level privileged authenticated attackers to arbitrarily deactivate, lock, and delete user accounts via a crafted session cookie.
2025-06-23T16:15:24.493
2025-07-02T19:10:16.237
Analyzed
CVSSv3.1: 8.1 (HIGH)
Type | Vendor | Product | Version/Range | Vulnerable? |
---|---|---|---|---|
Application | ncr | terminal_handler | 1.5.1 | Yes |