Opexus Foiaxpress Public Access Link vulnerabilities
4 known vulnerabilities affecting opexus/foiaxpress_public_access_link.
Total CVEs
4
CISA KEV
0
Public exploits
0
Exploited in wild
0
Severity breakdown
CRITICAL1HIGH1MEDIUM2
Vulnerabilities
Page 1 of 1
CVE-2025-58462P2CRITICALCVSS 9.8fixed in 11.13.1.02025-09-09
CVE-2025-58462 [CRITICAL] CWE-89 CVE-2025-58462: OPEXUS FOIAXpress Public Access Link (PAL) before version 11.13.1.0 allows SQL injection via SearchP
OPEXUS FOIAXpress Public Access Link (PAL) before version 11.13.1.0 allows SQL injection via SearchPopularDocs.aspx. A remote, unauthenticated attacker could read, write, or delete any content in the underlying database.
nvd
CVE-2025-54833P3HIGHCVSS 7.5≥ 11.1.0, < 11.12.3.02025-07-31
CVE-2025-54833 [HIGH] CWE-307 CVE-2025-54833: OPEXUS FOIAXpress Public Access Link (PAL) version v11.1.0 allows attackers to bypass account-lockou
OPEXUS FOIAXpress Public Access Link (PAL) version v11.1.0 allows attackers to bypass account-lockout and CAPTCHA protections. Unauthenticated remote attackers can more easily brute force passwords.
nvd
CVE-2025-54834P3MEDIUMCVSS 5.3≥ 11.1.0, < 11.12.3.02025-07-31
CVE-2025-54834 [MEDIUM] CWE-204 CVE-2025-54834: OPEXUS FOIAXpress Public Access Link (PAL) version v11.1.0 allows an unauthenticated, remote attacke
OPEXUS FOIAXpress Public Access Link (PAL) version v11.1.0 allows an unauthenticated, remote attacker to query the /App/CreateRequest.aspx endpoint to check for the existence of valid usernames. There are no rate-limiting mechanisms in place.
nvd
CVE-2025-54832P4MEDIUMCVSS 4.3≥ 11.1.0, < 11.12.3.02025-07-31
CVE-2025-54832 [MEDIUM] CWE-472 CVE-2025-54832: OPEXUS FOIAXpress Public Access Link (PAL), version v11.1.0, allows an authenticated user to add ent
OPEXUS FOIAXpress Public Access Link (PAL), version v11.1.0, allows an authenticated user to add entries to the list of states and territories.
nvd