PT-2026-26307 · Unknown · Opexus Ecase+1
Adam Rose
·
Publicado
2026-03-19
·
Atualizado
2026-03-23
·
CVE-2026-32865
CVSS v3.1
9.8
Crítica
| Vetor | AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
OPEXUS eComplaint and eCASE versions prior to 10.1.0.0
Description
The application includes the secret verification code in the HTTP response when a password reset is requested via the
ForcePasswordReset.aspx endpoint. An attacker with knowledge of a user's email address can reset the user's password and bypass security questions, as they are not required during the process. The vulnerable parameter is not explicitly mentioned.Recommendations
Versions prior to 10.1.0.0 should be updated to version 10.1.0.0 or later.
Correção
Information Disclosure
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Identificadores relacionados
Produtos afetados
Opexus Ecase
Opexus Ecomplaint