CVE-2026-22234

9.8CRITICAL

OPEXUS eCasePortal before version 9.0.45.0 allows an unauthenticated attacker to navigate to the 'Attachments.aspx' endpoint, iterate through predictable values of 'formid', and download or delete all

Опубликовано: 1/8/2026Обновлено: 1/13/2026

Описание

OPEXUS eCasePortal before version 9.0.45.0 allows an unauthenticated attacker to navigate to the 'Attachments.aspx' endpoint, iterate through predictable values of 'formid', and download or delete all user-uploaded files, or upload new files.

ИИ-АнализНа базе ИИ

Ссылки