PT-2026-26311 · Unknown · Opexus Ecase+1
Adam Rose
·
Published
2026-03-19
·
Updated
2026-03-23
·
CVE-2026-32869
CVSS v3.1
5.5
Medium
| Vector | AV:N/AC:L/PR:L/UI:R/S:U/C:L/I:L/A:L |
Name of the Vulnerable Software and Affected Versions
OPEXUS eComplaint and eCASE versions prior to 10.2.0.0
Description
The software does not properly sanitize input for the "Name of Organization" field when creating case information. An authenticated attacker can inject a cross-site scripting (XSS) payload. This payload is executed when a victim views the case information page, potentially compromising their session.
Recommendations
Update to version 10.2.0.0 or later.
Fix
XSS
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Opexus Ecase
Opexus Ecomplaint