Loading...
Loading...
passwordRequestPOST.jsp in Tyler Technologies TaxWeb 3.13.3.1 sends different HTTP status codes for invalid password-recovery requests depending on whether the user account exists, which allows remote attackers to enumerate account names via a series of requests to the (1) Assessor, (2) Recorder, or (3) Treasurer application.
October 28, 2013
April 29, 2026
See which npm, PyPI, Go, and Maven packages are affected by CVE-2013-6020
EchelonGraph automatically scans your cloud infrastructure and maps CVE exposure using blast radius analysis.