MEDIUM
OPEXUS FOIAXpress Public Access Link (PAL) state and territory list unauthorized modification
Published Jul 31, 2025
5.3
MEDIUMCVSS 4.0
EPSS 0.35%
Description
OPEXUS FOIAXpress Public Access Link (PAL), version v11.1.0, allows an authenticated user to add entries to the list of states and territories.
Affected products
-
Affected
- ≥ 11.1.0, < 11.12.3.0
Unaffected
- 11.12.3.0
Default status is the baseline for the product. Each version can override it (patched versions can be marked unaffected).
| Vendor | Product | Default status | Versions |
|---|---|---|---|
| Opexus | FOIAXpress Public Access Link (PAL) | unknown | Affected
Unaffected
|
- ≥ 11.1.0 · < 11.12.3.0
No data.
No Red Hat product state for this CVE.
No package ranges for this CVE.
Remediation
No remediation recorded yet.
Weaknesses (1)
References (4)
- https://docs.opexustech.com/docs/foiaxpress/11.12.0/FOIAXpress_Release_notes_11.12.3.0.pdf Release Notes
- https://euvd.enisa.europa.eu/vulnerability/EUVD-2025-23293 Advisory
- https://raw.githubusercontent.com/cisagov/CSAF/develop/csaf_files/IT/white/2025/va-25-174-01.json Product
- https://www.cve.org/CVERecord?id=CVE-2025-54832 Third Party Advisory
Change history (0)
No recorded changes yet.
Sources
CVE.org / MITRE
Status PUBLISHED
Assigner cisa-cg
Published Jul 31, 2025
Updated Aug 7, 2025
Reserved Jul 30, 2025
Link CVE-2025-54832
CISA Vulnrichment
Updated Jul 31, 2025
Red Hat
No data
GitHub
No data