CVE-2026-22233
EUVD-2026-147908.01.2026, 18:16
OPEXUS eCASE Audit allows an authenticated attacker to save JavaScript as a comment in the "Estimated Staff Hours" field. The JavaScript is executed whenever another user visits the Project Cost tab. Fixed in OPEXUS eCASE Audit 11.14.2.0.
Affected Products (NVD)
| Vendor | Product | Version |
|---|---|---|
| opexustech | ecase_audit | 11.4.0 ≤ 𝑥 < 11.14.2.0 |
𝑥
= Vulnerable software versions