Description
OPEXUS FOIAXpress Public Access Link (PAL) version v11.1.0 allows an unauthenticated, remote attacker to query the /App/CreateRequest.aspx endpoint to check for the existence of valid usernames. There are no rate-limiting mechanisms in place.
Published: 2025-07-31
Score: 6.9 Medium
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Analysis and contextual insights are available on OpenCVE Cloud.

Remediation

No vendor fix or workaround currently provided.

Additional remediation guidance may be available on OpenCVE Cloud.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
EUVD EUVD EUVD-2025-23292 OPEXUS FOIAXpress Public Access Link (PAL) version v11.1.0 allows an unauthenticated, remote attacker to query the /App/CreateRequest.aspx endpoint to check for the existence of valid usernames. There are no rate-limiting mechanisms in place.
History

Fri, 23 Jan 2026 02:45:00 +0000

Type Values Removed Values Added
First Time appeared Opexustech
Opexustech foiaxpress Public Access Link
CPEs cpe:2.3:a:opexus:foiaxpress_public_access_link:*:*:*:*:*:*:*:* cpe:2.3:a:opexustech:foiaxpress_public_access_link:*:*:*:*:*:*:*:*
Vendors & Products Opexus
Opexus foiaxpress Public Access Link
Opexustech
Opexustech foiaxpress Public Access Link

Fri, 12 Sep 2025 17:30:00 +0000

Type Values Removed Values Added
First Time appeared Opexus
Opexus foiaxpress Public Access Link
CPEs cpe:2.3:a:opexus:foiaxpress_public_access_link:*:*:*:*:*:*:*:*
Vendors & Products Opexus
Opexus foiaxpress Public Access Link

Thu, 31 Jul 2025 19:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'poc', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Thu, 31 Jul 2025 17:45:00 +0000

Type Values Removed Values Added
Description OPEXUS FOIAXpress Public Access Link (PAL) version v11.1.0 allows an unauthenticated, remote attacker to query the /App/CreateRequest.aspx endpoint to check for the existence of valid usernames. There are no rate-limiting mechanisms in place.
Title OPEXUS FOIAXpress Public Access Link (PAL) unauthenticated username enumeration
Weaknesses CWE-204
References
Metrics cvssV3_1

{'score': 5.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N'}

cvssV4_0

{'score': 6.9, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N'}


Subscriptions

Opexustech Foiaxpress Public Access Link
cve-icon MITRE

Status: PUBLISHED

Assigner: cisa-cg

Published:

Updated: 2025-07-31T18:16:59.684Z

Reserved: 2025-07-30T14:04:30.745Z

Link: CVE-2025-54834

cve-icon Vulnrichment

Updated: 2025-07-31T18:16:56.518Z

cve-icon NVD

Status : Analyzed

Published: 2025-07-31T18:15:43.250

Modified: 2026-01-23T02:38:53.650

Link: CVE-2025-54834

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

No data.

Weaknesses