JavaScript Injection Vulnerability in OPEXUS FOIAXpress
CVE-2025-61999

4.8MEDIUM

Key Information:

Vendor

Opexus

Vendor
CVE Published:
7 October 2025

What is CVE-2025-61999?

The OPEXUS FOIAXpress software prior to version 11.13.3.0 is susceptible to a JavaScript injection vulnerability that occurs when an administrative user uploads a logo in SVG format. This SVG may contain malicious JavaScript code that is executed in the context of other users browsing affected pages. Exploiting this vulnerability enables the attacker to manipulate user sessions, potentially compromising confidential information, such as session cookies and user credentials.

Affected Version(s)

FOIAXpress 0 < 11.13.3.0

FOIAXpress 11.13.3.0

References

CVSS V4

Score:
4.8
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
Unknown

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Aaron M. Ramirez, United States Department of Justice
Wesley Cuffee, United States Department of Justice
.