Cross-Site Scripting Vulnerability in OPEXUS eComplaint and eCASE Products
CVE-2026-32869

5.1MEDIUM

Key Information:

Vendor

Opexus

Vendor
CVE Published:
19 March 2026

What is CVE-2026-32869?

The OPEXUS eComplaint and eCASE applications prior to version 10.2.0.0 are susceptible to a Cross-Site Scripting (XSS) vulnerability due to improper sanitization of the 'Name of Organization' field during case information submission. This flaw allows an authenticated attacker to inject malicious scripts that are executed within the context of a victim's session when they access the affected case information page, potentially compromising user data and application integrity.

Affected Version(s)

eCASE 0 < 10.2.0.0

eComplaint 0 < 10.2.0.0

eCASE 10.2.0.0

References

CVSS V4

Score:
5.1
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
Unknown

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Adam Rose, CISA
.