CVE-2025-61998: OPEXUS FOIAXpress stored XSS via Hyperlink Manager
OPEXUS FOIAXpress before 11.13.3.0 allows an administrative user to inject JavaScript or other content as a URL within the Technical Support Hyperlink Manager. Injected content is executed in the context of other users when they click the malicious link. Successful exploitation allows the administrative user to perform actions on behalf of the target, including stealing session cookies, user credentials, or sensitive data.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-61998?
CVE-2025-61998 is classified as a significant security vulnerability due to its potential to allow JavaScript injection.
How do I fix CVE-2025-61998?
To fix CVE-2025-61998, upgrade OPEXUS FOIAXpress to version 11.13.3.0 or later.
What are the potential impacts of CVE-2025-61998?
The potential impacts of CVE-2025-61998 include unauthorized execution of JavaScript in the context of other users, leading to data exposure or session hijacking.
Which versions of OPEXUS FOIAXpress are affected by CVE-2025-61998?
OPEXUS FOIAXpress versions prior to 11.13.3.0 are affected by CVE-2025-61998.
Can CVE-2025-61998 be exploited remotely?
Yes, CVE-2025-61998 can be exploited remotely when a user clicks on a malicious link injected by an administrative user.