Impact
The vulnerability is an IDOR that allows an attacker without authentication to use the Attachments.aspx endpoint, iterating predictable formid values to access files uploaded by users. This flaw gives the attacker read, write, and delete capabilities over user‑uploaded content, potentially exposing confidential documents, corrupting data integrity, or disrupting access for legitimate users. The weakness is classified under CWE-639, which describes improper authorization of access to resources based on direct object references.
Affected Systems
OPEXUS eCasePortal versions prior to 9.0.45.0 are affected. Attacks target the Attachments.aspx endpoint exposed by the application, as documented by the vendor’s product listing.
Risk and Exploitability
The CVSS base score of 9.3 denotes critical severity. EPSS indicates a very low exploitation probability (<1%) and the vulnerability is not listed in CISA’s KEV catalog. Nonetheless, the flaw can be exploited by simply navigating to a known endpoint with predictable parameters. Based on the description, it is inferred that the attack requires minimal technical skill and does not require privileged access, making the risk notable for any unpatched deployment.
OpenCVE Enrichment