CVE-2025-58462: OPEXUS FOIAXpress PAL SQL injection
OPEXUS FOIAXpress Public Access Link (PAL) before version 11.13.1.0 allows SQL injection via SearchPopularDocs.aspx. A remote, unauthenticated attacker could read, write, or delete any content in the underlying database.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-58462?
CVE-2025-58462 has a critical severity level due to the potential for remote, unauthenticated SQL injection attacks.
How do I fix CVE-2025-58462?
To fix CVE-2025-58462, upgrade OPEXUS FOIAXpress Public Access Link to version 11.13.1.0 or later.
What impact does CVE-2025-58462 have on affected systems?
CVE-2025-58462 allows attackers to read, write, or delete content in the database, compromising data integrity and confidentiality.
Which versions of OPEXUS FOIAXpress are affected by CVE-2025-58462?
Versions of OPEXUS FOIAXpress Public Access Link prior to 11.13.1.0 are affected by CVE-2025-58462.
Is it possible to exploit CVE-2025-58462 remotely?
Yes, CVE-2025-58462 can be exploited remotely without authentication, making it particularly dangerous.