CVE-2026-32868
OPEXUS eComplaint and eCASE before 10.2.0.0 do not correctly sanitize the contents of first and last name fields in the 'My Information' screen. An authenticated attacker can inject parts of an XSS payload in the first and last name fields. The payload is executed when the full name is rendered. The attacker can run script in the context of a victim's session.
Vendor
Product
CWE
Yayın Tarihi
2026-03-19 16:16:03
Güncelleme
2026-03-30 13:06:05
Source Identifier
9119a7d8-5eab-497f-8521-727c672e3725
KEV Date Added
-