Description
OPEXUS eCASE Audit allows an authenticated attacker to save JavaScript as a comment in the "Estimated Staff Hours" field. The JavaScript is executed whenever another user visits the Project Cost tab. Fixed in OPEXUS eCASE Audit 11.14.2.0.
Problem types
CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
Product status
11.4.0 (custom) before 11.14.2.0
11.14.2.0
Credits
Aaron M. Ramirez, Son Nguyen, Wesley Cuffee, United States Department of Justice
References
docs.opexustech.com/...ase_Audit_Release_Notes_11.14.2.0.pdf (url)
raw.githubusercontent.com/...IT/white/2025/va-26-008-01.json (url)
www.cve.org/CVERecord?id=CVE-2026-22233 (url)