OPEXUS eComplaint and eCASE Stored Cross-Site Scripting Vulnerability via Profile Name Fields
Vulnerability
A stored cross-site scripting vulnerability has been identified in OPEXUS eComplaint and eCASE versions prior to 10.2.0.0. The issue arises because the applications do not properly sanitize the first and last name fields in user profiles. An authenticated attacker can inject parts of an XSS payload into these fields, which is executed when the user's full name is displayed. This allows the attacker to run scripts in the context of the victim's session.
Impact
Exploitation of this vulnerability allows for stored cross-site scripting, where injected scripts are executed in the context of the user's session.
Vulnerability Rating
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.
