PT-2026-26308 · Unknown · Opexus Ecase+1

Adam Rose

·

Published

2026-03-19

·

Updated

2026-03-23

·

CVE-2026-32866

CVSS v3.1

5.5

Medium

VectorAV:N/AC:L/PR:L/UI:R/S:U/C:L/I:L/A:L
Name of the Vulnerable Software and Affected Versions OPEXUS eComplaint and eCASE versions prior to 10.2.0.0
Description OPEXUS eComplaint and eCASE does not properly sanitize the first name and last name fields within a user profile. An authenticated attacker can inject parts of a cross-site scripting (XSS) payload into these fields. The injected payload is executed when a user’s full name is displayed. This allows the attacker to execute script in the context of a victim’s session.
Recommendations Update OPEXUS eComplaint and eCASE to version 10.2.0.0 or later.

Fix

XSS

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-32866

Affected Products

Opexus Ecase
Opexus Ecomplaint