OPEXUS eComplaint before version 9.0.45.0 allows an attacker to visit the the 'DocumentOpen.aspx' endpoint, iterate through predictable values of 'chargeNumber', and download any uploaded files.
References
Configurations
No configuration.
History
08 Jan 2026, 18:16
| Type | Values Removed | Values Added |
|---|---|---|
| New CVE |
Information
Published : 2026-01-08 18:16
Updated : 2026-01-08 18:16
NVD link : CVE-2026-22235
Mitre link : CVE-2026-22235
CVE.ORG link : CVE-2026-22235
JSON object : View
Products Affected
No product.
CWE
CWE-639
Authorization Bypass Through User-Controlled Key
