Cross-Site Scripting Vulnerability in OPEXUS eComplaint and eCASE
CVE-2026-32866
5.1MEDIUM
What is CVE-2026-32866?
The OPEXUS eComplaint and eCASE applications suffer from a vulnerability that fails to properly sanitize the first and last name fields in user profiles. This oversight enables authenticated attackers to inject malicious XSS payloads into these fields. When the full name is displayed, the payload executes in the context of the victim's session, potentially allowing attackers to compromise user data and launch further attacks. It is crucial to apply patches and updates to mitigate this risk.
Affected Version(s)
eCASE 0
eCASE 0 < 10.1.0.0
eCASE 10.1.0.0
