OPEXUS eCASE Audit Project Cost Stored Cross-Site Scripting Vulnerability
Vulnerability
A stored cross-site scripting vulnerability has been identified in OPEXUS eCASE Audit versions 11.4.0 prior to 11.14.2.0. This vulnerability allows authenticated attackers to inject JavaScript into the 'Estimated Staff Hours' field as a comment. The injected script is executed when another user accesses the Project Cost tab, potentially leading to unauthorized actions or data exposure.
Impact
Exploitation of this vulnerability allows for the execution of injected JavaScript in the context of the user viewing the Project Cost tab, which could be used to perform actions on behalf of the user or access sensitive information.
Remediation
Users can upgrade to OPEXUS eCASE Audit version 11.14.2.0 or later to address this vulnerability.
Vulnerability Rating
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.
