5.5
/ 10
MEDIUM
CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:L/I:L/A:L
Description
OPEXUS eCASE Audit allows an authenticated attacker to save JavaScript as a comment within the Document Check Out functionality. The JavaScript is executed whenever another user views the Action History Log. Fixed in OPEXUS eCASE Platform 11.14.1.0.
Basic Information
ID
CVE-2026-22231
Source
cisa-cg
Published
Jan 8, 2026 at 17:10
Modified
Jan 8, 2026 at 17:50
Affected Product
Vendor
OPEXUS
Product
eCASE Audit
Version
11.4.0
Affected Versions
OPEXUS eCASE Audit 11.4.0