CVE-2026-22235

HIGH

OPEXUS eComplaint <9.0.45.0 - Info Disclosure

Title source: llm
STIX 2.1

Description

OPEXUS eComplaint before version 9.0.45.0 allows an attacker to visit the the 'DocumentOpen.aspx' endpoint, iterate through predictable values of 'chargeNumber', and download any uploaded files.

References (2)

Core 2
Core References

Scores

CVSS v3 7.5
EPSS 0.0032
EPSS Percentile 24.0%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N

CISA SSVC

Vulnrichment
Exploitation poc
Automatable yes
Technical Impact partial

Details

CWE
CWE-639
Status published
Products (1)
opexustech/ecase_ecomplaint < 9.0.45.0
Published Jan 08, 2026
Tracked Since Feb 18, 2026