Tylertech

Court Case Management Plus

6 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
Medienbericht
  • EPSS 1.21%
  • Veröffentlicht 30.11.2023 18:15:09
  • Zuletzt bearbeitet 21.11.2024 08:43:41

Tyler Technologies Civil and Criminal Electronic Filing allows an unauthenticated, remote attacker to upload, delete, and view files by manipulating the Upload.aspx 'enky' parameter.

Medienbericht
  • EPSS 1.04%
  • Veröffentlicht 30.11.2023 18:15:09
  • Zuletzt bearbeitet 21.11.2024 08:43:41

Tyler Technologies Magistrate Court Case Management Plus allows an unauthenticated, remote attacker to upload, delete, and view files by manipulating the PDFViewer.aspx 'filename' parameter.

Medienbericht
  • EPSS 0.76%
  • Veröffentlicht 30.11.2023 18:15:09
  • Zuletzt bearbeitet 21.11.2024 08:43:44

Tyler Technologies Court Case Management Plus may store backups in a location that can be accessed by a remote, unauthenticated attacker. Backups may contain sensitive information such as database credentials.

Medienbericht
  • EPSS 0.99%
  • Veröffentlicht 30.11.2023 18:15:08
  • Zuletzt bearbeitet 21.11.2024 08:43:39

Tyler Technologies Court Case Management Plus allows a remote attacker to authenticate as any user by manipulating at least the 'CmWebSearchPfp/Login.aspx?xyzldk=' and 'payforprint_CM/Redirector.ashx?userid=' parameters. The vulnerable "pay for prin...

Medienbericht
  • EPSS 1.62%
  • Veröffentlicht 30.11.2023 18:15:08
  • Zuletzt bearbeitet 21.11.2024 08:43:39

Tyler Technologies Court Case Management Plus allows a remote, unauthenticated attacker to enumerate and access sensitive files using the tiffserver/tssp.aspx 'FN' and 'PN' parameters. This behavior is related to the use of a deprecated version of Aq...

Medienbericht
  • EPSS 1.62%
  • Veröffentlicht 30.11.2023 18:15:08
  • Zuletzt bearbeitet 21.11.2024 08:43:39

Tyler Technologies Court Case Management Plus allows a remote, unauthenticated attacker to enumerate directories using the tiffserver/te003.aspx or te004.aspx 'ifolder' parameter. This behavior is related to the use of a deprecated version of Aquafor...