OPEXUS FOIAXpress Stored Cross-Site Scripting Vulnerability via Banner Image Upload
Vulnerability
A stored cross-site scripting vulnerability has been identified in OPEXUS FOIAXpress versions prior to 11.13.3.0. This issue allows administrative users to inject JavaScript or other content into the Annual Report Enterprise Banner image upload field. The injected content is executed in the context of other users when they generate an Annual Report. Exploitation of this vulnerability enables the administrative user to perform actions on behalf of the affected user, such as stealing session cookies, user credentials, or sensitive data.
Impact
Exploitation of this vulnerability allows for stored cross-site scripting, where injected scripts are executed in the context of other users.
Remediation
Users can update to OPEXUS FOIAXpress version 11.13.3.0 or later, where this vulnerability has been addressed.
Vulnerability Rating
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.
