Description
OPEXUS FOIAXpress Public Access Link (PAL) before version 11.13.1.0 allows SQL injection via SearchPopularDocs.aspx. A remote, unauthenticated attacker could read, write, or delete any content in the underlying database.
Problem types
CWE-89 Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')
Product status
Any version before 11.13.1.0
11.13.1.0
Credits
, undefined
References
docs.opexustech.com/...OIAXpress_Release_Notes_11.13.1.0.pdf (url)
www.cve.org/CVERecord?id=CVE-2025-58462 (url)
github.com/...lop/csaf_files/IT/white/2025/va-25-252-01.json (url)