Tyler Technologies Court Case Management Plus allows a...
Moderate severity
Unreviewed
Published
Nov 30, 2023
to the GitHub Advisory Database
•
Updated Nov 30, 2023
Description
Published by the National Vulnerability Database
Nov 30, 2023
Published to the GitHub Advisory Database
Nov 30, 2023
Last updated
Nov 30, 2023
Tyler Technologies Court Case Management Plus allows a remote, unauthenticated attacker to enumerate and access sensitive files using the tiffserver/tssp.aspx 'FN' and 'PN' parameters. This behavior is related to the use of a deprecated version of Aquaforest TIFF Server, possibly 2.x. The vulnerable Aquaforest TIFF Server feature was removed on or around 2023-11-01. Insecure configuration issues in Aquaforest TIFF Server are identified separately as CVE-2023-6352. CVE-2023-6343 is similar to CVE-2020-9323. CVE-2023-6343 is related to or partially caused by CVE-2023-6352.
References