CVE-2025-54834
31.07.2025, 18:15
OPEXUS FOIAXpress Public Access Link (PAL) version v11.1.0 allows an unauthenticated, remote attacker to query the /App/CreateRequest.aspx endpoint to check for the existence of valid usernames. There are no rate-limiting mechanisms in place.Enginsight
Vendor | Product | Version |
---|---|---|
opexus | foiaxpress_public_access_link | 11.1.0 ≤ 𝑥 < 11.12.3.0 |
𝑥
= Vulnerable software versions
Common Weakness Enumeration