---
id: CVE-2025-61997
title: >-
  OPEXUS FOIAXpress before 11.13.3.0 allows an administrative user to inject
  JavaScript or other content within the Annual Report Enterprise Banner image
  upload field
summary: >-
  OPEXUS FOIAXpress before 11.13.3.0 allows an administrative user to inject
  JavaScript or other content within the Annual Report Enterprise Banner image
  upload field. Injected content is executed in the context of other users when
  they ge…
severity: medium
cvss: 4.3
cvssVector: 'CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:U/C:L/I:L/A:L'
cwe:
  - CWE-79
vendor: opexustech
product: foiaxpress
affected:
  - foiaxpress < 11.13.3.0
patched:
  - foiaxpress 11.13.3.0
published: '2025-10-08'
updated: '2026-10-08'
sourceUpdated: '2026-10-08T13:10:00.200'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2025-61997'
references:
  - url: >-
      https://docs.opexustech.com/docs/foiaxpress/11.13.0/FOIAXpress_Release_Notes_11.13.3.0.pdf
    label: 9119a7d8-5eab-497f-8521-727c672e3725
  - url: >-
      https://raw.githubusercontent.com/cisagov/CSAF/develop/csaf_files/IT/white/2025/va-25-280-01.json
    label: 9119a7d8-5eab-497f-8521-727c672e3725
  - url: 'https://www.cve.org/CVERecord?id=CVE-2025-61997'
    label: 9119a7d8-5eab-497f-8521-727c672e3725
tags:
  - nvd
epss: 0.00241
epssPercentile: 0.13951
ingestedAt: '2026-10-08T13:42:54.987Z'
---

## Overview

OPEXUS FOIAXpress before 11.13.3.0 allows an administrative user to inject JavaScript or other content within the Annual Report Enterprise Banner image upload field. Injected content is executed in the context of other users when they generate an Annual Report. Successful exploitation allows the administrative user to perform actions on behalf of the target, including stealing session cookies, user credentials, or sensitive data.

## Affected

- `foiaxpress < 11.13.3.0`

## Remediation

Upgrade past the affected range:

- `foiaxpress 11.13.3.0`
