Vulnerabilities (CVE)

Filtered by vendor Opexustech Subscribe
Filtered by product Ecase Portal
Total 1 CVE
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2026-22234 1 Opexustech 1 Ecase Portal 2026-02-18 N/A 9.8 CRITICAL
OPEXUS eCasePortal before version 9.0.45.0 allows an unauthenticated attacker to navigate to the 'Attachments.aspx' endpoint, iterate through predictable values of 'formid', and download or delete all user-uploaded files, or upload new files.