Логотип exploitDog
bind:CVE-2026-22234
Консоль
Логотип exploitDog

exploitDog

bind:CVE-2026-22234

Количество 2

Количество 2

nvd логотип

CVE-2026-22234

около 1 месяца назад

OPEXUS eCasePortal before version 9.0.45.0 allows an unauthenticated attacker to navigate to the 'Attachments.aspx' endpoint, iterate through predictable values of 'formid', and download or delete all user-uploaded files, or upload new files.

CVSS3: 9.8
EPSS: Низкий
github логотип

GHSA-rw5g-57c7-74m2

около 1 месяца назад

OPEXUS eCasePortal before version 9.0.45.0 allows an unauthenticated attacker to navigate to the 'Attachments.aspx' endpoint, iterate through predictable values of 'formid', and download or delete all user-uploaded files, or upload new files.

CVSS3: 9.8
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
nvd логотип
CVE-2026-22234

OPEXUS eCasePortal before version 9.0.45.0 allows an unauthenticated attacker to navigate to the 'Attachments.aspx' endpoint, iterate through predictable values of 'formid', and download or delete all user-uploaded files, or upload new files.

CVSS3: 9.8
0%
Низкий
около 1 месяца назад
github логотип
GHSA-rw5g-57c7-74m2

OPEXUS eCasePortal before version 9.0.45.0 allows an unauthenticated attacker to navigate to the 'Attachments.aspx' endpoint, iterate through predictable values of 'formid', and download or delete all user-uploaded files, or upload new files.

CVSS3: 9.8
0%
Низкий
около 1 месяца назад

Уязвимостей на страницу