CVE-2025-61997 Details
Description
OPEXUS FOIAXpress before 11.13.3.0 allows an administrative user to inject JavaScript or other content within the Annual Report Enterprise Banner image upload field. Injected content is executed in the context of other users when they generate an Annual Report. Successful exploitation allows the administrative user to perform actions on behalf of the target, including stealing session cookies, user credentials, or sensitive data.
A stored cross-site scripting vulnerability has been identified in OPEXUS FOIAXpress versions prior to 11.13.3.0. This issue allows administrative users to inject JavaScript or other content into the Annual Report Enterprise Banner image upload field. The injected content is executed in the context of other users when they generate an Annual Report. Exploitation of this vulnerability enables the administrative user to perform actions on behalf of the affected user, such as stealing session cookies, user credentials, or sensitive data.
Users can update to OPEXUS FOIAXpress version 11.13.3.0 or later, where this vulnerability has been addressed.
Metrics
CVSS 4.0 Severity and Vector Strings:
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
CISA-ADP
Assessed Oct 10, 2025CISA-ADP
Assessed Oct 7, 2025References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://docs.opexustech.com/docs/foiaxpress/11.13.0/FOIAXpress_Release_Notes_11.13.3.0.pdf | Cybersecurity and Infrastructure Security Agency (CISA) U.S. Civilian Government | Release Notes |
| https://raw.githubusercontent.com/cisagov/CSAF/develop/csaf_files/IT/white/2025/va-25-280-01.json | Cybersecurity and Infrastructure Security Agency (CISA) U.S. Civilian Government | Third Party Advisory |
| https://www.cve.org/CVERecord?id=CVE-2025-61997 | Cybersecurity and Infrastructure Security Agency (CISA) U.S. Civilian Government | Third Party Advisory |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-79 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') | Cybersecurity and Infrastructure Security Agency (CISA) U.S. Civilian Government |
Affected Products
| Product | Versions |
|---|---|
| opexustech foiaxpress | < 11.13.3.0 |
CPE
Remediation
| |
Change History
4 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jun 17, 2026 | CVE Modified | Cybersecurity and Infrastructure Security Agency (CISA) U.S. Civilian Government |
| Jun 17, 2026 | CVE Modified | CISA-ADP |
| Oct 22, 2025 | Initial Analysis | [email protected] |
| Oct 8, 2025 | New CVE Received | Cybersecurity and Infrastructure Security Agency (CISA) U.S. Civilian Government |