Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2023-6342

Опубликовано: 30 нояб. 2023
Источник: nvd
CVSS3: 5.3
CVSS3: 9.8
EPSS Низкий

Описание

Tyler Technologies Court Case Management Plus allows a remote attacker to authenticate as any user by manipulating at least the 'CmWebSearchPfp/Login.aspx?xyzldk=' and 'payforprint_CM/Redirector.ashx?userid=' parameters. The vulnerable "pay for print" feature was removed on or around 2023-11-01.

Уязвимые конфигурации

Конфигурация 1
cpe:2.3:a:tylertech:court_case_management_plus:-:*:*:*:*:*:*:*

EPSS

Процентиль: 76%
0.00967
Низкий

5.3 Medium

CVSS3

9.8 Critical

CVSS3

Дефекты

CWE-287
CWE-287

Связанные уязвимости

CVSS3: 5.3
github
около 2 лет назад

Tyler Technologies Court Case Management Plus allows a remote attacker to authenticate as any user by manipulating at least the 'CmWebSearchPfp/Login.aspx?xyzldk=' and 'payforprint_CM/Redirector.ashx?userid=' parameters. The vulnerable "pay for print" feature was removed on or around 2023-11-01.

EPSS

Процентиль: 76%
0.00967
Низкий

5.3 Medium

CVSS3

9.8 Critical

CVSS3

Дефекты

CWE-287
CWE-287