OPEXUS eComplaint before version 9.0.45.0 allows an attacker to visit the the 'DocumentOpen.aspx' endpoint, iterate through predictable values of 'chargeNumber', and download any uploaded files.
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-22235.json"
[ { "events": [ { "introduced": "0" }, { "fixed": "9.0.45.0" } ] } ]