PatchSiren

OPEXUS CVE debriefs

These pages are published after PatchSiren validates generated defensive summaries against stored public CVE and source evidence.

MEDIUM OPEXUS CVE published 2026-03-19

CVE-2026-32868

CVE-2026-32868 is a medium-severity vulnerability in OPEXUS eComplaint and eCASE software. The issue arises from improper sanitization of first and last name fields in the 'My Information' screen, allowing authenticated attackers to inject XSS payloads. The payload executes when the full name is rendered, enabling the attacker to run scripts in the context of a victim's session. This vulnerability was rep [truncated]

MEDIUM OPEXUS CVE published 2026-03-19

CVE-2026-32866

CVE-2026-32866 is a stored XSS vulnerability in OPEXUS eComplaint and eCASE before version 10.2.0.0. The vulnerability occurs because the application does not properly sanitize the first and last name fields in a user's profile. An authenticated attacker can inject parts of an XSS payload into these fields. The payload is executed when the user's full name is rendered, allowing the attacker to run script [truncated]

CRITICAL OPEXUS CVE published 2026-03-19

CVE-2026-32865

CVE-2026-32865 is a critical vulnerability in OPEXUS eComplaint and eCASE software. The vulnerability occurs when the software includes the secret verification code in the HTTP response during a password reset via 'ForcePasswordReset.aspx'. This allows an attacker who knows an existing user's email address to reset the user's password and security questions without needing to answer existing security ques [truncated]

MEDIUM OPEXUS CVE published 2026-01-08

CVE-2026-22233

CVE-2026-22233 is a medium severity vulnerability in OPEXUS eCASE Audit, allowing an authenticated attacker to save JavaScript as a comment in the 'Estimated Staff Hours' field. The JavaScript is executed whenever another user visits the Project Cost tab. This vulnerability was fixed in OPEXUS eCASE Audit 11.14.2.0. The CVSS score for this vulnerability is 5.5. The vulnerability was published on January 8, 2026.

MEDIUM OPEXUS CVE published 2026-01-08

CVE-2026-22232

CVE-2026-22232 is a stored cross-site scripting (XSS) vulnerability in the OPEXUS eCASE Audit software. An authenticated attacker can exploit this vulnerability by saving JavaScript code in the 'A or SIC Number' field within the Project Setup functionality. When another user views the project, the JavaScript code is executed. This vulnerability was fixed in OPEXUS eCASE Audit version 11.14.2.0. The Common [truncated]

HIGH OPEXUS CVE published 2026-01-08

CVE-2026-22230

CVE-2026-22230 is a HIGH-severity vulnerability in OPEXUS eCASE Audit, allowing an authenticated attacker to modify client-side JavaScript or craft HTTP requests to access functions or buttons that have been disabled or blocked by an administrator. The vulnerability was published on January 8, 2026, and has a CVSS score of 7.6. The issue is fixed in eCASE Platform 11.14.1.0. Users of affected versions sho [truncated]

HIGH OPEXUS CVE published 2026-01-07

CVE-2026-22235

CVE-2026-22235 is a vulnerability in OPEXUS eComplaint before version 9.0.45.0. An attacker can exploit this vulnerability by visiting the 'DocumentOpen.aspx' endpoint and iterating through predictable values of 'chargeNumber' to download any uploaded files. The vulnerability has a CVSS score of 7.5 and is classified as HIGH severity. The CVE was published on January 7, 2026, and has not been modified sin [truncated]

CRITICAL OPEXUS CVE published 2026-01-07

CVE-2026-22234

CVE-2026-22234 is a critical unauthenticated IDOR vulnerability in OPEXUS eCasePortal before version 9.0.45.0. This vulnerability allows attackers to navigate to the 'Attachments.aspx' endpoint, iterate through predictable values of 'formid', and download or delete all user-uploaded files, or upload new files. The vulnerability has a CVSS score of 9.8 and is considered critical. The issue was publicly dis [truncated]