PT-2026-26307 · Unknown · Opexus Ecase+1

Adam Rose

·

Publicado

2026-03-19

·

Atualizado

2026-03-23

·

CVE-2026-32865

CVSS v3.1

9.8

Crítica

VetorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions OPEXUS eComplaint and eCASE versions prior to 10.1.0.0
Description The application includes the secret verification code in the HTTP response when a password reset is requested via the ForcePasswordReset.aspx endpoint. An attacker with knowledge of a user's email address can reset the user's password and bypass security questions, as they are not required during the process. The vulnerable parameter is not explicitly mentioned.
Recommendations Versions prior to 10.1.0.0 should be updated to version 10.1.0.0 or later.

Correção

Information Disclosure

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2026-32865

Produtos afetados

Opexus Ecase
Opexus Ecomplaint