PT-2025-41200 · Unknown · Opexus Foiaxpress

Aaron M. Ramirez

+1

·

Published

2025-10-07

·

Updated

2025-10-22

·

CVE-2025-61998

CVSS v3.1

4.8

Medium

VectorAV:N/AC:L/PR:H/UI:R/S:C/C:L/I:L/A:N
Name of the Vulnerable Software and Affected Versions OPEXUS FOIAXpress versions prior to 11.13.3.0
Description OPEXUS FOIAXpress before version 11.13.3.0 allows an administrative user to inject JavaScript or other content as a URL within the Technical Support Hyperlink Manager. This injected content is executed in the context of other users when they click the malicious link. Successful exploitation allows the administrative user to perform actions on behalf of the target, potentially including stealing session cookies, user credentials, or sensitive data.
Recommendations Update OPEXUS FOIAXpress to version 11.13.3.0 or later.

Fix

XSS

Weakness Enumeration

Related Identifiers

CVE-2025-61998

Affected Products

Opexus Foiaxpress