← back
CVE-2025-61999

OPEXUS FOIAXpress stored XSS via logo image

CVSS 4.8 MEDIUMEPSS 0.2%CWE-79
Vexday Risk Score
13Low
SSVC decision (CISA)
Track
No exploitation signal → monitor
CVSS 4.8EPSS 0.2%KEV nãoPoC Nuclei Metasploit Patch
Lifecycle
07 Oct 2025Published on NVD
Recommendation: Monitor — no exploitation signal at the moment.
OPEXUS FOIAXpress before 11.13.3.0 allows an administrative user to upload JavaScript or other content embedded in an SVG image used as a logo. Injected content is executed in the context of other users when they view affected pages. Successful exploitation allows the administrative user to perform actions on behalf of the target, including stealing session cookies, user credentials, or sensitive data.
CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:P/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N
Affected products
OPEXUS · FOIAXpress

Want to know if your infrastructure is exposed to this?

Talk to TrueHacking →