5.5
/ 10
MEDIUM
CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:L/I:L/A:L
Description
OPEXUS eCASE Audit allows an authenticated attacker to save JavaScript as a comment in the "Estimated Staff Hours" field. The JavaScript is executed whenever another user visits the Project Cost tab. Fixed in OPEXUS eCASE Audit 11.14.2.0.
Basic Information
ID
CVE-2026-22233
Source
cisa-cg
Published
Jan 8, 2026 at 17:11
Modified
Jan 8, 2026 at 17:51
Affected Product
Vendor
OPEXUS
Product
eCASE Audit
Version
11.4.0
Affected Versions
OPEXUS eCASE Audit 11.4.0