cvedb.io
CVE-2026-22232
MEDIUM · CVSS 5.5
EPSS exploitation probability: 0%
Published 2026-01-08T18:16:00.063 · Last modified 2026-06-17T10:19:36.037

Summary

OPEXUS eCASE Audit allows an authenticated attacker to save JavaScript in the "A or SIC Number" field within the Project Setup functionality. The JavaScript is executed whenever another user views the project. Fixed in OPEXUS eCASE Audit 11.14.2.0.

Affected products

opexustech — ecase_audit

Does this affect you?

Add your gear to cvedb and we'll alert you only when opexustech ships something exploited.

Check my exposure →

References

This product uses data from the NVD API but is not endorsed or certified by the NVD. Informational only; not professional security advice.