Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1000 CNY

100.0%

CVE-2023-6344— Tyler Technologies Court Case Management Plus use of Aquaforest TIFF Server te003.aspx and te004.aspx allows authentication bypass

CVSS 5.3 · Medium EPSS 1.62% · P82
Get alerts for future matching vulnerabilitiesLog in to subscribe

I. Basic Information for CVE-2023-6344

Vulnerability Information

Have questions about the vulnerability? See if Shenlong's analysis helps!
View Shenlong Deep Dive ↗

Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.

Vulnerability Title
Tyler Technologies Court Case Management Plus use of Aquaforest TIFF Server te003.aspx and te004.aspx allows authentication bypass
Source: NVD (National Vulnerability Database)
Vulnerability Description
Tyler Technologies Court Case Management Plus allows a remote, unauthenticated attacker to enumerate directories using the tiffserver/te003.aspx or te004.aspx 'ifolder' parameter. This behavior is related to the use of a deprecated version of Aquaforest TIFF Server, possibly 2.x. The vulnerable Aquaforest TIFF Server feature was removed on or around 2023-11-01. Insecure configuration issues in Aquaforest TIFF Server are identified separately as CVE-2023-6352. CVE-2023-6343 is related to or partially caused by CVE-2023-6352.
Source: NVD (National Vulnerability Database)
CVSS Information
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
Source: NVD (National Vulnerability Database)
Vulnerability Type
认证机制不恰当
Source: NVD (National Vulnerability Database)
Vulnerability Title
Tyler Technologies Magistrate Court Case Management Plus 安全漏洞
Source: CNNVD (China National Vulnerability Database)
Vulnerability Description
Tyler Technologies Magistrate Court Case Management Plus是Tyler Technologies公司的一个地方法院案件管理系统。 Tyler Technologies Magistrate Court Case Management Plus存在安全漏洞。远程攻击者利用该漏洞可以使用tiffserver/te003.aspx或te004.aspx的“ifolder”参数枚举目录。
Source: CNNVD (China National Vulnerability Database)
CVSS Information
N/A
Source: CNNVD (China National Vulnerability Database)
Vulnerability Type
N/A
Source: CNNVD (China National Vulnerability Database)

Affected Products

VendorProductAffected VersionsCPESubscribe
Tyler TechnologiesCourt Case Management Plus 0 ~ ~2023-11-01 -

II. Public POCs for CVE-2023-6344

#POC DescriptionSource LinkShenlong Link
AI-Generated POCPremium

No public POC found.

Login to generate AI POC

III. Intelligence Information for CVE-2023-6344

登录查看更多情报信息。

Same Patch Batch · Tyler Technologies · 2023-11-30 · 6 CVEs total

CVE-2023-63425.3 MEDIUMTyler Technologies Court Case Management Plus "pay for print" allows authentication bypass
CVE-2023-63435.3 MEDIUMTyler Technologies Court Case Management Plus use of Aquaforest TIFF Server tssp.aspx allo
CVE-2023-63535.3 MEDIUMTyler Technologies Civil and Criminal Electronic Filing Upload.aspx allows authentication
CVE-2023-63545.3 MEDIUMTyler Technologies Magistrate Court Case Management Plus PDFViewer.aspx allows authenticat
CVE-2023-63755.3 MEDIUMTyler Technologies Magistrate Court Case Management Plus stores backups insecurely

IV. Related Vulnerabilities

V. Comments for CVE-2023-6344

No comments yet


Leave a comment