Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
Tyler Technologies Court Case Management Plus use of Aquaforest TIFF Server tssp.aspx allows authentication bypass
Vulnerability Description
Tyler Technologies Court Case Management Plus allows a remote, unauthenticated attacker to enumerate and access sensitive files using the tiffserver/tssp.aspx 'FN' and 'PN' parameters. This behavior is related to the use of a deprecated version of Aquaforest TIFF Server, possibly 2.x. The vulnerable Aquaforest TIFF Server feature was removed on or around 2023-11-01. Insecure configuration issues in Aquaforest TIFF Server are identified separately as CVE-2023-6352. CVE-2023-6343 is similar to CVE-2020-9323. CVE-2023-6343 is related to or partially caused by CVE-2023-6352.
CVSS Information
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
Vulnerability Type
认证机制不恰当
Vulnerability Title
Tyler Technologies Magistrate Court Case Management Plus 安全漏洞
Vulnerability Description
Tyler Technologies Magistrate Court Case Management Plus是Tyler Technologies公司的一个地方法院案件管理系统。 Tyler Technologies Magistrate Court Case Management Plus存在安全漏洞。远程攻击者利用该漏洞可以使用tiffserver/tssp.aspx的“FN”和“PN”参数枚举和访问敏感文件。
CVSS Information
N/A
Vulnerability Type
N/A