Mr-n0b3dy / CVE-2023-42362

Geek Repo:Geek Repo

Github PK Tool:Github PK Tool

CVE-2023-42362

Author: Abdelrahman Mohamed (Mr-n0b3dy)

Vulnerability Name: Unrestricted File Upload that led to ATO

Severity: High

Product: NCR teller web app

Version: 4.4.0

Description:

The Unrestricted File Upload leading to Stored Cross-Site Scripting (XSS) vulnerability is a security issue identified within the web application. This vulnerability arises due to a lack of proper input validation in the file upload functionality.

Impact:

Attackers can upload a malicious file containing JavaScript code that enables them to hijack the admin session, which is already stored in the local storage. This breach could result in an account takeover of the admin account, granting them full access to administrator functionalities.

Recommendations:

Install the latest version of the NCR Teller web app.

About