Untriaged
Permalink
CVE-2026-32868
5.5 MEDIUM
- CVSS version: 3.1
- Attack vector (AV): NETWORK
- Attack complexity (AC): LOW
- Privileges required (PR): LOW
- User interaction (UI): REQUIRED
- Scope (S): UNCHANGED
- Confidentiality impact (C): LOW
- Integrity impact (I): LOW
- Availability impact (A): LOW
OPEXUS eComplaint and eCASE XSS via my information
OPEXUS eComplaint and eCASE before 10.2.0.0 do not correctly sanitize the contents of first and last name fields in the 'My Information' screen. An authenticated attacker can inject parts of an XSS payload in the first and last name fields. The payload is executed when the full name is rendered. The attacker can run script in the context of a victim's session.
Affected products
eCASE
- <10.2.0.0
- ==10.2.0.0
eComplaint
- <10.2.0.0
- ==10.2.0.0
Matching in nixpkgs
pkgs.haskellPackages.titlecase
Convert English Words to Title Case
pkgs.python312Packages.titlecase
Python library to capitalize strings as specified by the New York Times
pkgs.python313Packages.titlecase
Python library to capitalize strings as specified by the New York Times
pkgs.python314Packages.titlecase
Python library to capitalize strings as specified by the New York Times
Package maintainers
-
@peti Peter Simons <simons@cryp.to>