Tyler Technologies Magistrate Court Case Management Plus PDFViewer.aspx allows authentication bypass
CVE-2023-6354
9.4CRITICAL
What is CVE-2023-6354?
Tyler Technologies Magistrate Court Case Management Plus is vulnerable to unauthorized actions due to improper validation of the 'filename' parameter in PDFViewer.aspx. This security loophole allows unauthenticated remote attackers to upload, delete, and view sensitive documents, potentially compromising court records and other critical files. As such vulnerabilities pose substantial risks to data privacy and integrity, it’s essential for users to apply security updates and follow best practices for protecting sensitive information.
Affected Version(s)
Magistrate Court Case Management Plus 0
