CNNVD-202510-1209 Information
CNNVD ID
CNNVD-202510-1209
Related CVE
- CNNVD Published: 2025-10-08
Description (Chinese)
OPEXUS FOIAXpress是美国OPEXUS公司的一个信息公开管理软件。 OPEXUS FOIAXpress 11.13.3.0之前版本存在安全漏洞,该漏洞源于管理员用户可在年度报告企业横幅图像上传字段中注入JavaScript或其他内容,可能导致跨站脚本攻击。
Description (English)
OPEXUS FOIAXpress is an information public management software of the United States company OPEXUS. OPEXUS FOIAXpress 11.13.3.0 has a security loophole, which stems from the fact that administrator users can upload JavaScript or other content in the annual report enterprise banner image, which may result in a cross-site script attack.
Hazard Level
High
Vulnerability Type
其他
Affected Vendor
OPEXUS
Published
2025-10-08
Last Modified
2026-02-24
References
https://docs.opexustech.com/docs/foiaxpress/11.13.0/FOIAXpress_Release_Notes_11.13.3.0.pdf https://raw.githubusercontent.com/cisagov/CSAF/develop/csaf_files/IT/white/2025/va-25-280-01.json https://www.cve.org/CVERecord?id=CVE-2025-61997