XSS Vulnerability in OPEXUS eComplaint and eCASE Products
CVE-2026-32868

5.1MEDIUM

Key Information:

Vendor

Opexus

Vendor
CVE Published:
19 March 2026

What is CVE-2026-32868?

In versions of OPEXUS eComplaint and eCASE prior to 10.2.0.0, the application fails to properly sanitize user inputs in the 'My Information' section, specifically in the first and last name fields. This allows an authenticated attacker to inject malicious scripts that can be executed in the context of the victim's session, compromising the security and integrity of user data. It highlights the importance of implementing robust sanitization methods to safeguard against XSS attacks in web applications.

Affected Version(s)

eCASE 0 < 10.2.0.0

eComplaint 0 < 10.2.0.0

eCASE 10.2.0.0

References

CVSS V4

Score:
5.1
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
Unknown

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Adam Rose, CISA
.