CVE-2025-54834
Severity CVSS v4.0:
MEDIUM
Type:
Unavailable / Other
Publication date:
31/07/2025
Last modified:
23/01/2026
Description
OPEXUS FOIAXpress Public Access Link (PAL) version v11.1.0 allows an unauthenticated, remote attacker to query the /App/CreateRequest.aspx endpoint to check for the existence of valid usernames. There are no rate-limiting mechanisms in place.
Impact
Base Score 4.0
6.90
Severity 4.0
MEDIUM
Base Score 3.x
5.30
Severity 3.x
MEDIUM
Vulnerable products and versions
| CPE | From | Up to |
|---|---|---|
| cpe:2.3:a:opexustech:foiaxpress_public_access_link:*:*:*:*:*:*:*:* | 11.1.0 (including) | 11.12.3.0 (excluding) |
To consult the complete list of CPE names with products and versions, see this page



