CVE-2026-22234
EUVD-2026-148608.01.2026, 18:16
OPEXUS eCasePortal before version 9.0.45.0 allows an unauthenticated attacker to navigate to the 'Attachments.aspx' endpoint, iterate through predictable values of 'formid', and download or delete all user-uploaded files, or upload new files.Enginsight
Affected Products (NVD)
| Vendor | Product | Version |
|---|---|---|
| opexustech | ecase_portal | 𝑥 < 9.0.45.0 |
𝑥
= Vulnerable software versions
Common Weakness Enumeration