CVE-2026-32869: OPEXUS eComplaint and eCASE XSS via Name of Organization field
OPEXUS eComplaint and eCASE before 10.2.0.0 do not correctly sanitize the contents of the "Name of Organization" field when filling out case information. An authenticated attacker can inject an XSS payload which is executed in the context of a victim's session when they visit the case information page.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2026-32869?
CVE-2026-32869 is classified as a high-severity vulnerability due to the potential for XSS attacks.
How do I fix CVE-2026-32869?
To fix CVE-2026-32869, upgrade OPEXUS eComplaint and eCASE to version 10.2.0.0 or later.
Who is affected by CVE-2026-32869?
Organizations using OPEXUS eComplaint and eCASE versions before 10.2.0.0 are affected by CVE-2026-32869.
What type of vulnerability is CVE-2026-32869?
CVE-2026-32869 is a Cross-Site Scripting (XSS) vulnerability.
Can CVE-2026-32869 be exploited remotely?
Yes, CVE-2026-32869 can be exploited by authenticated attackers who can inject XSS payloads through the affected form.