HarborGuard / CVE
Back to search
HIGHCVE-2026-22235Published Modified CNA cisa-cg

CVE-2026-22235: OPEXUS eComplaint IDOR

OPEXUS eComplaint before version 9.0.45.0 allows an attacker to visit the the 'DocumentOpen.aspx' endpoint, iterate through predictable values of 'chargeNumber', and download any uploaded files.

Metrics

CVSS v4.0
8.7
Severity
HIGH
Fixed in
9.0.45.0
Affected Products
1

Fix available

9.0.45.0
Affected packages
  • OPEXUS / eComplaint
    < 9.0.45.0 (from 0)
    Fixed in 9.0.45.0
CVSS Vector
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N
References