PT-2026-2174 · Opexus · Opexus Ecase Audit

Aaron M. Ramirez

+3

·

Published

2026-01-08

·

Updated

2026-01-09

·

CVE-2026-22232

CVSS v3.1

5.5

Medium

VectorAV:N/AC:L/PR:L/UI:R/S:U/C:L/I:L/A:L
Name of the Vulnerable Software and Affected Versions OPEXUS eCASE Audit versions prior to 11.14.2.0
Description OPEXUS eCASE Audit allows an authenticated attacker to save JavaScript in the “A or SIC Number” field within the Project Setup functionality. This JavaScript is executed when another user views the project. The affected field is used for project setup and allows for the storage of malicious code. The A or SIC Number field is the entry point for this issue.
Recommendations Upgrade to OPEXUS eCASE Audit version 11.14.2.0 or later.

Fix

XSS

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-22232

Affected Products

Opexus Ecase Audit