cbcvebase.

Opexus Foiaxpress Public Access Link vulnerabilities

4 known vulnerabilities affecting opexus/foiaxpress_public_access_link.

Total CVEs
4
CISA KEV
0
Public exploits
0
Exploited in wild
0
Severity breakdown
CRITICAL1HIGH1MEDIUM2

Vulnerabilities

Page 1 of 1
CVE-2025-58462P2CRITICALCVSS 9.8fixed in 11.13.1.02025-09-09
CVE-2025-58462 [CRITICAL] CWE-89 CVE-2025-58462: OPEXUS FOIAXpress Public Access Link (PAL) before version 11.13.1.0 allows SQL injection via SearchP OPEXUS FOIAXpress Public Access Link (PAL) before version 11.13.1.0 allows SQL injection via SearchPopularDocs.aspx. A remote, unauthenticated attacker could read, write, or delete any content in the underlying database.
nvd
CVE-2025-54833P3HIGHCVSS 7.5≥ 11.1.0, < 11.12.3.02025-07-31
CVE-2025-54833 [HIGH] CWE-307 CVE-2025-54833: OPEXUS FOIAXpress Public Access Link (PAL) version v11.1.0 allows attackers to bypass account-lockou OPEXUS FOIAXpress Public Access Link (PAL) version v11.1.0 allows attackers to bypass account-lockout and CAPTCHA protections. Unauthenticated remote attackers can more easily brute force passwords.
nvd
CVE-2025-54834P3MEDIUMCVSS 5.3≥ 11.1.0, < 11.12.3.02025-07-31
CVE-2025-54834 [MEDIUM] CWE-204 CVE-2025-54834: OPEXUS FOIAXpress Public Access Link (PAL) version v11.1.0 allows an unauthenticated, remote attacke OPEXUS FOIAXpress Public Access Link (PAL) version v11.1.0 allows an unauthenticated, remote attacker to query the /App/CreateRequest.aspx endpoint to check for the existence of valid usernames. There are no rate-limiting mechanisms in place.
nvd
CVE-2025-54832P4MEDIUMCVSS 4.3≥ 11.1.0, < 11.12.3.02025-07-31
CVE-2025-54832 [MEDIUM] CWE-472 CVE-2025-54832: OPEXUS FOIAXpress Public Access Link (PAL), version v11.1.0, allows an authenticated user to add ent OPEXUS FOIAXpress Public Access Link (PAL), version v11.1.0, allows an authenticated user to add entries to the list of states and territories.
nvd
Opexus Foiaxpress Public Access Link vulnerabilities | cvebase