Vulnerabilities (CVE)

Filtered by vendor Tylertech Subscribe
Filtered by product Court Case Management Plus
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2023-6342 1 Tylertech 1 Court Case Management Plus 2023-12-06 N/A 9.8 CRITICAL
Tyler Technologies Court Case Management Plus allows a remote attacker to authenticate as any user by manipulating at least the 'CmWebSearchPfp/Login.aspx?xyzldk=' and 'payforprint_CM/Redirector.ashx?userid=' parameters. The vulnerable "pay for print" feature was removed on or around 2023-11-01.
CVE-2023-6353 1 Tylertech 1 Court Case Management Plus 2023-12-06 N/A 9.4 CRITICAL
Tyler Technologies Civil and Criminal Electronic Filing allows an unauthenticated, remote attacker to upload, delete, and view files by manipulating the Upload.aspx 'enky' parameter.
CVE-2023-6354 1 Tylertech 1 Court Case Management Plus 2023-12-06 N/A 9.4 CRITICAL
Tyler Technologies Magistrate Court Case Management Plus allows an unauthenticated, remote attacker to upload, delete, and view files by manipulating the PDFViewer.aspx 'filename' parameter.