Critical severity9.8NVD Advisory· Published Sep 9, 2025· Updated Jun 17, 2026
CVE-2025-58462
CVE-2025-58462
Description
OPEXUS FOIAXpress Public Access Link (PAL) before version 11.13.1.0 allows SQL injection via SearchPopularDocs.aspx. A remote, unauthenticated attacker could read, write, or delete any content in the underlying database.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
4- cpe:2.3:a:opexustech:foiaxpress_public_access_link:*:*:*:*:*:*:*:*Range: <11.13.1.0
<11.13.1.0+ 1 more
- (no CPE)range: <11.13.1.0
- (no CPE)range: 0
- Range: <11.13.1.0
Patches
Vulnerability mechanics
References
3- github.com/cisagov/CSAF/blob/develop/csaf_files/IT/white/2025/va-25-252-01.jsonnvdThird Party Advisory
- www.cve.org/CVERecordnvdThird Party Advisory
- docs.opexustech.com/docs/foiaxpress/11.13.0/FOIAXpress_Release_Notes_11.13.1.0.pdfnvdRelease Notes
News mentions
0No linked articles in our index yet.