OPEXUS FOIAXpress Stored Cross-Site Scripting Vulnerability in Annual Report Template

Vulnerability

A stored cross-site scripting vulnerability has been identified in OPEXUS FOIAXpress versions prior to 11.13.3.0. This issue allows administrative users to inject JavaScript or other content into the Annual Report Template. The injected content is executed in the context of other users when they generate an Annual Report. Exploitation of this vulnerability enables the administrative user to perform actions on behalf of the user, such as stealing session cookies, user credentials, or sensitive data.

Impact

Exploitation of this vulnerability allows for stored cross-site scripting, where injected content is executed in the context of other users.

Remediation

Users can update to OPEXUS FOIAXpress version 11.13.3.0 or later, where this vulnerability has been addressed.

Added: Oct 8, 2025, 12:23 AM
Updated: Oct 8, 2025, 12:23 AM

Vulnerability Rating

Custom Algorithm
spread
0.0
impact
4.2
exploitability
4.5
remediation
0.0
relevance
0.6
threat
0.0
urgency
2.9
incentive
1.7

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.