CVE 4.8 MEDIUM

OPEXUS eCASE Audit Project Setup stored XSS_CVE-2026-22232

4.8 / 10
MEDIUM
CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:A/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N

Description

OPEXUS eCASE Audit allows an authenticated attacker to save JavaScript in the "A or SIC Number" field within the Project Setup functionality. The JavaScript is executed whenever another user views the project. Fixed in OPEXUS eCASE Audit 11.14.2.0.

Basic Information

ID CVE-2026-22232
Source cisa-cg
Published Jan 8, 2026 at 17:10
Modified Jan 8, 2026 at 17:51

Affected Product

Vendor OPEXUS
Product eCASE Audit
Version 11.4.0
Affected Versions OPEXUS eCASE Audit 11.4.0

CWE Classification

References

💭 Join the Security Discussion

🔒 Your email address will not be published. Required fields are marked *

⚠️ Please be respectful and constructive in your comments. Security discussions should remain professional.