CVE-2025-61997: OPEXUS FOIAXpress stored XSS via banner image
OPEXUS FOIAXpress before 11.13.3.0 allows an administrative user to inject JavaScript or other content within the Annual Report Enterprise Banner image upload field. Injected content is executed in the context of other users when they generate an Annual Report. Successful exploitation allows the administrative user to perform actions on behalf of the target, including stealing session cookies, user credentials, or sensitive data.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-61997?
CVE-2025-61997 is classified as a high severity vulnerability due to its potential for cross-site scripting (XSS) attacks.
How do I fix CVE-2025-61997?
To fix CVE-2025-61997, upgrade OPEXUS FOIAXpress to version 11.13.3.0 or later.
What types of attacks can exploit CVE-2025-61997?
CVE-2025-61997 can be exploited to perform cross-site scripting (XSS) attacks through the Annual Report Enterprise Banner image upload field.
Who is affected by CVE-2025-61997?
Administrative users of OPEXUS FOIAXpress versions prior to 11.13.3.0 are affected by CVE-2025-61997.
What functionality is compromised due to CVE-2025-61997?
CVE-2025-61997 compromises the ability of users to safely generate Annual Reports, allowing malicious content to be executed.