---
id: CVE-2025-61998
title: >-
  OPEXUS FOIAXpress before 11.13.3.0 allows an administrative user to inject
  JavaScript or other content as a URL within the Technical Support Hyperlink
  Manager
summary: >-
  OPEXUS FOIAXpress before 11.13.3.0 allows an administrative user to inject
  JavaScript or other content as a URL within the Technical Support Hyperlink
  Manager. Injected content is executed in the context of other users when they
  click th…
severity: medium
cvss: 4.3
cvssVector: 'CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:U/C:L/I:L/A:L'
cwe:
  - CWE-79
vendor: opexustech
product: foiaxpress
affected:
  - foiaxpress < 11.13.3.0
patched:
  - foiaxpress 11.13.3.0
published: '2025-10-08'
updated: '2026-10-08'
sourceUpdated: '2026-10-08T13:10:00.200'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2025-61998'
references:
  - url: >-
      https://docs.opexustech.com/docs/foiaxpress/11.13.0/FOIAXpress_Release_Notes_11.13.3.0.pdf
    label: 9119a7d8-5eab-497f-8521-727c672e3725
  - url: >-
      https://raw.githubusercontent.com/cisagov/CSAF/develop/csaf_files/IT/white/2025/va-25-280-01.json
    label: 9119a7d8-5eab-497f-8521-727c672e3725
  - url: 'https://www.cve.org/CVERecord?id=CVE-2025-61998'
    label: 9119a7d8-5eab-497f-8521-727c672e3725
tags:
  - nvd
epss: 0.00241
epssPercentile: 0.13951
ingestedAt: '2026-10-08T13:42:54.987Z'
---

## Overview

OPEXUS FOIAXpress before 11.13.3.0 allows an administrative user to inject JavaScript or other content as a URL within the Technical Support Hyperlink Manager. Injected content is executed in the context of other users when they click the malicious link. Successful exploitation allows the administrative user to perform actions on behalf of the target, including stealing session cookies, user credentials, or sensitive data.

## Affected

- `foiaxpress < 11.13.3.0`

## Remediation

Upgrade past the affected range:

- `foiaxpress 11.13.3.0`
