CVE-2026-22233

OPEXUS eCASE Audit allows an authenticated attacker to save JavaScript as a comment in the "Estimated Staff Hours" field. The JavaScript is executed whenever another user visits the Project Cost tab. Fixed in OPEXUS eCASE Audit 11.14.2.0.
Configurations

Configuration 1 (hide)

cpe:2.3:a:opexustech:ecase_audit:*:*:*:*:*:*:*:*

History

17 Jun 2026, 10:19

Type Values Removed Values Added
Summary
  • (es) OPEXUS eCASE Audit permite a un atacante autenticado guardar JavaScript como un comentario en el campo 'Horas de personal estimadas'. El JavaScript se ejecuta cada vez que otro usuario visita la pestaña 'Costo del proyecto'. Corregido en OPEXUS eCASE Audit 11.14.2.0.

05 Feb 2026, 19:09

Type Values Removed Values Added
CPE cpe:2.3:a:opexustech:ecase_audit:*:*:*:*:*:*:*:*
First Time Opexustech ecase Audit
Opexustech
References () https://docs.opexustech.com/docs/oig/audit/eCase_Audit_Release_Notes_11.14.2.0.pdf - () https://docs.opexustech.com/docs/oig/audit/eCase_Audit_Release_Notes_11.14.2.0.pdf - Release Notes
References () https://raw.githubusercontent.com/cisagov/CSAF/develop/csaf_files/IT/white/2025/va-26-008-01.json - () https://raw.githubusercontent.com/cisagov/CSAF/develop/csaf_files/IT/white/2025/va-26-008-01.json - Broken Link
References () https://www.cve.org/CVERecord?id=CVE-2026-22233 - () https://www.cve.org/CVERecord?id=CVE-2026-22233 - Third Party Advisory

08 Jan 2026, 18:16

Type Values Removed Values Added
New CVE

Information

Published : 2026-01-08 18:16

Updated : 2026-06-17 10:19


NVD link : CVE-2026-22233

Mitre link : CVE-2026-22233

CVE.ORG link : CVE-2026-22233


JSON object : View

Products Affected

opexustech

  • ecase_audit
CWE
CWE-79

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')