OPEXUS eComplaint and eCASE Cross-Site Scripting Vulnerability

Vulnerability

A cross-site scripting (XSS) vulnerability has been identified in OPEXUS eComplaint and eCASE versions prior to 10.2.0.0. The issue arises because the applications do not properly sanitize the first and last name fields in the 'My Information' screen. An authenticated attacker can inject parts of an XSS payload into these fields, which is executed when the full name is displayed. This allows the attacker to run scripts in the context of the victim's session.

Impact

Exploitation of this vulnerability allows for cross-site scripting, where an attacker can inject and execute scripts in the context of the user's session.

Remediation

Users can upgrade to OPEXUS eComplaint or eCASE version 10.2.0.0 or later to address this vulnerability.

Added: Mar 19, 2026, 4:19 PM
Updated: Mar 19, 2026, 4:19 PM

Vulnerability Rating

Custom Algorithm
spread
0.0
impact
1.7
exploitability
5.0
remediation
0.0
relevance
4.1
threat
0.0
urgency
2.9
incentive
0.0

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.