OPEXUS FOIAXpress Stored Cross-Site Scripting Vulnerability via Hyperlink Manager
Vulnerability
A stored cross-site scripting vulnerability has been identified in OPEXUS FOIAXpress versions prior to 11.13.3.0. This issue allows administrative users to inject JavaScript or other content as a URL within the Technical Support Hyperlink Manager. The injected content is executed in the context of other users when they click the malicious link. Exploitation of this vulnerability enables the administrative user to perform actions on behalf of the target user, potentially leading to the theft of session cookies, user credentials, or other sensitive data.
Impact
Exploitation of this vulnerability allows for stored cross-site scripting, where injected content is executed in the context of other users.
Remediation
Users can update to OPEXUS FOIAXpress version 11.13.3.0 or later to address this vulnerability.
Vulnerability Rating
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.
