cvedb.io
CVE-2025-61997
MEDIUM · CVSS 4.3
EPSS exploitation probability: 0%
Published 2025-10-08T00:15:34.070 · Last modified 2026-06-17T09:51:10.640

Summary

OPEXUS FOIAXpress before 11.13.3.0 allows an administrative user to inject JavaScript or other content within the Annual Report Enterprise Banner image upload field. Injected content is executed in the context of other users when they generate an Annual Report. Successful exploitation allows the administrative user to perform actions on behalf of the target, including stealing session cookies, user credentials, or sensitive data.

Affected products

opexustech — foiaxpress

Does this affect you?

Add your gear to cvedb and we'll alert you only when opexustech ships something exploited.

Check my exposure →

References

This product uses data from the NVD API but is not endorsed or certified by the NVD. Informational only; not professional security advice.