OPEXUS eCASE Audit Project Setup Stored Cross-Site Scripting Vulnerability
Vulnerability
A stored cross-site scripting vulnerability has been identified in OPEXUS eCASE Audit versions 11.4.0 prior to 11.14.2.0. This vulnerability allows authenticated attackers to inject JavaScript into the 'A or SIC Number' field within the Project Setup feature. The injected JavaScript is executed when another user views the project, potentially leading to unauthorized actions or data exposure.
Impact
Exploitation of this vulnerability allows for the execution of injected JavaScript in the context of the user viewing the project, which could be used to perform actions on behalf of the user or access sensitive information.
Remediation
Users can upgrade to OPEXUS eCASE Audit version 11.14.2.0 or later to address this vulnerability.
Vulnerability Rating
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.
