PT-2026-2176 · Opexus · Opexus Ecaseportal
Zach Crosman
·
Published
2026-01-08
·
Updated
2026-02-18
·
CVE-2026-22234
CVSS v3.1
9.8
Critical
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
OPEXUS eCasePortal versions prior to 9.0.45.0
Description
OPEXUS eCasePortal allows an unauthenticated attacker to access and manipulate user-uploaded files. An attacker can navigate to the ''Attachments.aspx'' endpoint and, by iterating through predictable values of the
formid parameter, download or delete existing files, and upload new ones. The issue stems from an Insecure Direct Object Reference (IDOR) condition.Recommendations
Versions prior to 9.0.45.0 should be updated to version 9.0.45.0 or later.
Fix
IDOR
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Opexus Ecaseportal