CYBER CODE RED

Get real-time updates on Telegram

P5Verified

CVE-2025-61997: foiaxpress before 11.13.3.0 (exclusive); +1 more affected products

CVE-2025-61997. CVSS 3.1 base score 4.8 (MEDIUM, NVD). EPSS 0.00241 (percentile 0.13904), scored 2026-10-06.

Affected technology

foiaxpress · before 11.13.3.0 (exclusive)
opexustech

FOIAXpress · 0 to before 11.13.3.0
OPEXUS

Description’s affected range: before 11.13.3.0

Component: Not specified by the source

Attack conditions (Source advisory, CVSS 4.0): Network (remote) · High privileges required · Passive user interaction

What an attacker can do

An administrative user can inject JavaScript or other content within the Annual Report Enterprise Banner image upload field. Source advisory’s CVSS 4.0 assessment (base score 4.8/10) rates confidentiality, integrity and availability impact as low.

Published

CWE
CWE-79
CCR priority
19.3 /100 (P5)
CVSS 3.1
4.8 /10 · CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:C/C:L/I:L/A:N · NVD
EPSS
0.00241 · percentile 0.13961 · 2026-10-08
KEV
no

Provenance

Stable permalink: https://cybercodered.org/item/cve-cve-2025-61997.html