CVE

CVE-2023-6342

Severity:
CRITICAL
Type:
CWE-287 Authentication Issues
Publication date:
30/11/2023
Last modified:
06/12/2023

Description

Tyler Technologies Court Case Management Plus allows a remote attacker to authenticate as any user by manipulating at least the &amp;#39;CmWebSearchPfp/Login.aspx?xyzldk=&amp;#39; and <br /> &amp;#39;payforprint_CM/Redirector.ashx?userid=&amp;#39; parameters. The vulnerable "pay for print" feature was removed on or around 2023-11-01.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:tylertech:court_case_management_plus:-:*:*:*:*:*:*:*