CNNVD-202601-1411 Information
Jan 08, 2026
cve
CNNVD ID
CNNVD-202601-1411
Related CVE
- CNNVD Published: 2026-01-08
Description (Chinese)
OPEXUS eCASE Audit是美国OPEXUS公司的一个审计管理软件。 OPEXUS eCASE Audit存在安全漏洞,该漏洞源于认证攻击者可在Estimated Staff Hours字段中保存JavaScript,可能导致跨站脚本攻击。
Description (English)
OPEXUS eCASE Audit is an audit management software for the United States company OPEXUS. OPEXUS eCASE Audit has a security loophole, which stems from the certification that the assailant can save JavaScript in the Estimated Staff Hours field, which could result in a cross-site script attack.
Hazard Level
High
Vulnerability Type
其他
Affected Vendor
OPEXUS
Published
2026-01-08
Last Modified
2026-02-24
References
https://docs.opexustech.com/docs/oig/audit/eCase_Audit_Release_Notes_11.14.2.0.pdf https://raw.githubusercontent.com/cisagov/CSAF/develop/csaf_files/IT/white/2025/va-26-008-01.json https://www.cve.org/CVERecord?id=CVE-2026-22233