Home
HIGH: 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:NHIGH: 8.7 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:NDefault status
unknown
Any version before 9.0.45.0
affected
9.0.45.0
unaffected
Description
OPEXUS eComplaint before version 9.0.45.0 allows an attacker to visit the the 'DocumentOpen.aspx' endpoint, iterate through predictable values of 'chargeNumber', and download any uploaded files.
Problem types
CWE-639 Authorization Bypass Through User-Controlled Key
Product status
Any version before 9.0.45.0
9.0.45.0
Credits
Zach Crosman, CISA
References
raw.githubusercontent.com/...IT/white/2025/va-26-008-02.json (url)
www.cve.org/CVERecord?id=CVE-2026-22235 (url)