Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-rw5g-57c7-74m2

Опубликовано: 08 янв. 2026
Источник: github
Github: Не прошло ревью
CVSS4: 9.3
CVSS3: 9.8

Описание

OPEXUS eCasePortal before version 9.0.45.0 allows an unauthenticated attacker to navigate to the 'Attachments.aspx' endpoint, iterate through predictable values of 'formid', and download or delete all user-uploaded files, or upload new files.

OPEXUS eCasePortal before version 9.0.45.0 allows an unauthenticated attacker to navigate to the 'Attachments.aspx' endpoint, iterate through predictable values of 'formid', and download or delete all user-uploaded files, or upload new files.

EPSS

Процентиль: 22%
0.00072
Низкий

9.3 Critical

CVSS4

9.8 Critical

CVSS3

Дефекты

CWE-639

Связанные уязвимости

CVSS3: 9.8
nvd
30 дней назад

OPEXUS eCasePortal before version 9.0.45.0 allows an unauthenticated attacker to navigate to the 'Attachments.aspx' endpoint, iterate through predictable values of 'formid', and download or delete all user-uploaded files, or upload new files.

EPSS

Процентиль: 22%
0.00072
Низкий

9.3 Critical

CVSS4

9.8 Critical

CVSS3

Дефекты

CWE-639