Home
MEDIUM: 4.3 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:NMEDIUM: 5.3 CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:NDefault status
unknown
11.1.0 (custom) before 11.12.3.0
affected
11.12.3.0
unaffected
Description
OPEXUS FOIAXpress Public Access Link (PAL), version v11.1.0, allows an authenticated user to add entries to the list of states and territories.
Problem types
CWE-472 External Control of Assumed-Immutable Web Parameter
Product status
11.1.0 (custom) before 11.12.3.0
11.12.3.0
Credits
Nathan Spidle, CISA
References
raw.githubusercontent.com/...IT/white/2025/va-25-174-01.json (url)
www.cve.org/CVERecord?id=CVE-2025-54832 (url)
docs.opexustech.com/...OIAXpress_Release_notes_11.12.3.0.pdf (url)