CVE-2026-22231: OPEXUS eCASE Audit Document Check Out stored XSS
OPEXUS eCASE Audit allows an authenticated attacker to save JavaScript as a comment within the Document Check Out functionality. The JavaScript is executed whenever another user views the Action History Log. Fixed in OPEXUS eCASE Platform 11.14.1.0.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2026-22231?
CVE-2026-22231 has a medium severity level due to the potential for cross-site scripting (XSS) attacks when JavaScript is executed in the Action History Log.
How do I fix CVE-2026-22231?
To fix CVE-2026-22231, upgrade OPEXUS eCASE Platform to version 11.14.1.0 or later.
What type of attack does CVE-2026-22231 allow?
CVE-2026-22231 allows authenticated attackers to execute JavaScript in the context of other users through manipulated comments.
Who is affected by CVE-2026-22231?
CVE-2026-22231 affects users of OPEXUS eCASE Platform versions prior to 11.14.1.0.
What functionality is exploited in CVE-2026-22231?
CVE-2026-22231 exploits the Document Check Out functionality by allowing JavaScript to be saved as a comment.