MEDIUM
OPEXUS FOIAXpress Public Access Link (PAL) unauthenticated username enumeration
Published Jul 31, 2025
6.9
MEDIUMCVSS 4.0
EPSS 0.49%
Description
OPEXUS FOIAXpress Public Access Link (PAL) version v11.1.0 allows an unauthenticated, remote attacker to query the /App/CreateRequest.aspx endpoint to check for the existence of valid usernames. There are no rate-limiting mechanisms in place.
Affected products
-
- Version 11.1.0StatusaffectedConstraints<11.12.3.0
- Version 11.12.3.0StatusunaffectedConstraints-
- Version
Default status is the baseline for the product, each version can override it (e.g. patched versions marked unaffected).
| Vendor | Product | Default status | Versions | |||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|
| Opexus | FOIAXpress Public Access Link (PAL) | n/a |
|
- ≥ 11.1.0 · < 11.12.3.0
No data.
No Red Hat product state for this CVE.
No package ranges for this CVE.
Remediation
No remediation recorded yet.
Weaknesses (1)
References (4)
- https://docs.opexustech.com/docs/foiaxpress/11.12.0/FOIAXpress_Release_notes_11.12.3.0.pdf Release Notes
- https://euvd.enisa.europa.eu/vulnerability/EUVD-2025-23292 Advisory
- https://raw.githubusercontent.com/cisagov/CSAF/develop/csaf_files/IT/white/2025/va-25-174-01.json Product
- https://www.cve.org/CVERecord?id=CVE-2025-54834 Third Party Advisory
Change history (0)
No recorded changes yet.
Sources
CVE.org / MITRE
Status PUBLISHED
Assigner cisa-cg
Published Jul 31, 2025
Updated Jul 31, 2025
Reserved Jul 30, 2025
Link CVE-2025-54834
CISA Vulnrichment
Updated Jul 31, 2025
ENISA EUVD
EUVD-2025-23292 Assigner cisa-cg
Published Jul 31, 2025
Updated Jul 31, 2025
Exploited since n/a
Link EUVD-2025-23292