PT-2025-36976 · Opexus · Opexus Foiaxpress Public Access Link

Undefined

·

Published

2025-09-09

·

Updated

2025-09-26

·

CVE-2025-58462

CVSS v3.1

9.8

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions: OPEXUS FOIAXpress Public Access Link (PAL) versions prior to 11.13.1.0
Description: A SQL injection flaw exists in OPEXUS FOIAXpress Public Access Link (PAL) via the SearchPopularDocs.aspx page. A remote, unauthenticated attacker could potentially read, write, or delete content within the underlying database.
Recommendations: Upgrade to version 11.13.1.0 or later.

Fix

SQL injection

Weakness Enumeration

Related Identifiers

CVE-2025-58462

Affected Products

Opexus Foiaxpress Public Access Link