CVE-2026-22232

MEDIUM

OPEXUS eCASE Audit 11.4.0-11.14.1.9 - Authenticated Stored Cross-Site Scripting in Project Setup A or SIC Number Field

Title source: llm
STIX 2.1

Description

OPEXUS eCASE Audit allows an authenticated attacker to save JavaScript in the "A or SIC Number" field within the Project Setup functionality. The JavaScript is executed whenever another user views the project. Fixed in OPEXUS eCASE Audit 11.14.2.0.

References (3)

Core 3

Scores

CVSS v3 5.5
EPSS 0.0021
EPSS Percentile 10.9%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:L/I:L/A:L

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact partial

Details

CWE
CWE-79
Status published
Products (1)
opexustech/ecase_audit 11.4.0 - 11.14.2.0
Published Jan 08, 2026
Tracked Since Feb 18, 2026