Tyler Technologies Court Case Management Plus allows a remote attacker to authenticate as any user by manipulating at least the CmWebSearchPfp/Login.aspx?xyzldk= and payforprint_CM/Redirector.ashx?userid= parameters. The vulnerable pay for print feature was removed on or around 2023-11-01.
When an actor claims to have a given identity, the product does not prove or insufficiently proves that the claim is correct.
Name | Vendor | Start Version | End Version |
---|---|---|---|
Court_case_management_plus | Tylertech | - (including) | - (including) |