---
id: CVE-2025-61999
title: >-
  OPEXUS FOIAXpress before 11.13.3.0 allows an administrative user to upload
  JavaScript or other content embedded in an SVG image used as a logo
summary: >-
  OPEXUS FOIAXpress before 11.13.3.0 allows an administrative user to upload
  JavaScript or other content embedded in an SVG image used as a logo. Injected
  content is executed in the context of other users when they view affected
  pages. Suc…
severity: medium
cvss: 4.3
cvssVector: 'CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:U/C:L/I:L/A:L'
cwe:
  - CWE-79
vendor: opexustech
product: foiaxpress
affected:
  - foiaxpress < 11.13.3.0
patched:
  - foiaxpress 11.13.3.0
published: '2025-10-08'
updated: '2026-10-08'
sourceUpdated: '2026-10-08T13:10:00.200'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2025-61999'
references:
  - url: >-
      https://docs.opexustech.com/docs/foiaxpress/11.13.0/FOIAXpress_Release_Notes_11.13.3.0.pdf
    label: 9119a7d8-5eab-497f-8521-727c672e3725
  - url: >-
      https://raw.githubusercontent.com/cisagov/CSAF/develop/csaf_files/IT/white/2025/va-25-280-01.json
    label: 9119a7d8-5eab-497f-8521-727c672e3725
  - url: 'https://www.cve.org/CVERecord?id=CVE-2025-61999'
    label: 9119a7d8-5eab-497f-8521-727c672e3725
tags:
  - nvd
epss: 0.00241
epssPercentile: 0.13951
ingestedAt: '2026-10-08T13:42:54.988Z'
---

## Overview

OPEXUS FOIAXpress before 11.13.3.0 allows an administrative user to upload JavaScript or other content embedded in an SVG image used as a logo. Injected content is executed in the context of other users when they view affected pages. Successful exploitation allows the administrative user to perform actions on behalf of the target, including stealing session cookies, user credentials, or sensitive data.

## Affected

- `foiaxpress < 11.13.3.0`

## Remediation

Upgrade past the affected range:

- `foiaxpress 11.13.3.0`
