Vulnerability Details CVE-2025-54834
OPEXUS FOIAXpress Public Access Link (PAL) version v11.1.0 allows an unauthenticated, remote attacker to query the /App/CreateRequest.aspx endpoint to check for the existence of valid usernames. There are no rate-limiting mechanisms in place.
Exploit prediction scoring system (EPSS) score
EPSS Score 0.0
EPSS Ranking 10.4%
CVSS Severity
CVSS v3 Score 5.3
Products affected by CVE-2025-54834
-
cpe:2.3:a:opexustech:foiaxpress_public_access_link:11.1.0
-
cpe:2.3:a:opexustech:foiaxpress_public_access_link:11.1.1
-
cpe:2.3:a:opexustech:foiaxpress_public_access_link:11.10.0
-
cpe:2.3:a:opexustech:foiaxpress_public_access_link:11.11.0
-
cpe:2.3:a:opexustech:foiaxpress_public_access_link:11.11.1
-
cpe:2.3:a:opexustech:foiaxpress_public_access_link:11.11.2
-
cpe:2.3:a:opexustech:foiaxpress_public_access_link:11.11.2.1
-
cpe:2.3:a:opexustech:foiaxpress_public_access_link:11.12.1.0
-
cpe:2.3:a:opexustech:foiaxpress_public_access_link:11.12.2.0
-
cpe:2.3:a:opexustech:foiaxpress_public_access_link:11.3.0
-
cpe:2.3:a:opexustech:foiaxpress_public_access_link:11.3.1
-
cpe:2.3:a:opexustech:foiaxpress_public_access_link:11.3.2
-
cpe:2.3:a:opexustech:foiaxpress_public_access_link:11.3.3
-
cpe:2.3:a:opexustech:foiaxpress_public_access_link:11.3.4
-
cpe:2.3:a:opexustech:foiaxpress_public_access_link:11.3.5
-
cpe:2.3:a:opexustech:foiaxpress_public_access_link:11.4.0
-
cpe:2.3:a:opexustech:foiaxpress_public_access_link:11.4.1
-
cpe:2.3:a:opexustech:foiaxpress_public_access_link:11.4.2
-
cpe:2.3:a:opexustech:foiaxpress_public_access_link:11.5.0
-
cpe:2.3:a:opexustech:foiaxpress_public_access_link:11.5.1
-
cpe:2.3:a:opexustech:foiaxpress_public_access_link:11.5.2
-
cpe:2.3:a:opexustech:foiaxpress_public_access_link:11.5.4
-
cpe:2.3:a:opexustech:foiaxpress_public_access_link:11.5.5
-
cpe:2.3:a:opexustech:foiaxpress_public_access_link:11.7.0
-
cpe:2.3:a:opexustech:foiaxpress_public_access_link:11.7.2
-
cpe:2.3:a:opexustech:foiaxpress_public_access_link:11.8.0
-
cpe:2.3:a:opexustech:foiaxpress_public_access_link:11.8.1