Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2025-27489 | OPEXUS FOIAXpress Public Access Link (PAL) before version 11.13.1.0 allows SQL injection via SearchPopularDocs.aspx. A remote, unauthenticated attacker could read, write, or delete any content in the underlying database. |
Fri, 26 Sep 2025 13:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Opexustech
Opexustech foiaxpress Public Access Link |
|
| CPEs | cpe:2.3:a:opexustech:foiaxpress_public_access_link:*:*:*:*:*:*:*:* | |
| Vendors & Products |
Opexustech
Opexustech foiaxpress Public Access Link |
Fri, 12 Sep 2025 14:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Fri, 12 Sep 2025 09:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Opexus
Opexus foiaxpress Pal |
|
| Vendors & Products |
Opexus
Opexus foiaxpress Pal |
Tue, 09 Sep 2025 21:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | OPEXUS FOIAXpress Public Access Link (PAL) before version 11.13.1.0 allows SQL injection via SearchPopularDocs.aspx. A remote, unauthenticated attacker could read, write, or delete any content in the underlying database. | |
| Title | OPEXUS FOIAXpress PAL SQL injection | |
| Weaknesses | CWE-89 | |
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: cisa-cg
Published:
Updated: 2026-02-26T17:48:47.966Z
Reserved: 2025-09-02T21:00:53.965Z
Link: CVE-2025-58462
Updated: 2025-09-12T13:41:24.561Z
Status : Analyzed
Published: 2025-09-09T21:15:38.377
Modified: 2025-09-26T13:39:18.220
Link: CVE-2025-58462
No data.
OpenCVE Enrichment
Updated: 2025-09-12T09:11:45Z
EUVD