Unrated severityNVD Advisory· Published Sep 9, 2025· Updated Feb 26, 2026
OPEXUS FOIAXpress PAL SQL injection
CVE-2025-58462
Description
OPEXUS FOIAXpress Public Access Link (PAL) before version 11.13.1.0 allows SQL injection via SearchPopularDocs.aspx. A remote, unauthenticated attacker could read, write, or delete any content in the underlying database.
Affected products
3<11.13.1.0+ 1 more
- (no CPE)range: <11.13.1.0
- (no CPE)range: 0
Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
3News mentions
0No linked articles in our index yet.