{"id":"CVE-2025-58462","title":"OPEXUS FOIAXpress Public Access Link (PAL) before version 11.13.1.0 allows SQL injection via SearchPopularDocs.aspx","summary":"OPEXUS FOIAXpress Public Access Link (PAL) before version 11.13.1.0 allows SQL injection via SearchPopularDocs.aspx. A remote, unauthenticated attacker could read, write, or delete any content in the underlying database.","severity":"critical","cvss":9.8,"cvssVector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","cwe":["CWE-89"],"vendor":"opexustech","product":"foiaxpress_public_access_link","affected":["foiaxpress_public_access_link < 11.13.1.0"],"patched":["foiaxpress_public_access_link 11.13.1.0"],"published":"2025-09-09","updated":"2026-09-30","sourceUpdated":"2026-09-30T23:10:00.237","source":"NVD","sourceUrl":"https://nvd.nist.gov/vuln/detail/CVE-2025-58462","references":[{"url":"https://docs.opexustech.com/docs/foiaxpress/11.13.0/FOIAXpress_Release_Notes_11.13.1.0.pdf","label":"9119a7d8-5eab-497f-8521-727c672e3725"},{"url":"https://github.com/cisagov/CSAF/blob/develop/csaf_files/IT/white/2025/va-25-252-01.json","label":"9119a7d8-5eab-497f-8521-727c672e3725"},{"url":"https://www.cve.org/CVERecord?id=CVE-2025-58462","label":"9119a7d8-5eab-497f-8521-727c672e3725"}],"tags":["nvd"],"epss":0.0066,"epssPercentile":0.49666,"ingestedAt":"2026-09-30T23:29:32.377Z","slug":"CVE-2025-58462","body":"## Overview\n\nOPEXUS FOIAXpress Public Access Link (PAL) before version 11.13.1.0 allows SQL injection via SearchPopularDocs.aspx. A remote, unauthenticated attacker could read, write, or delete any content in the underlying database.\n\n## Affected\n\n- `foiaxpress_public_access_link < 11.13.1.0`\n\n## Remediation\n\nUpgrade past the affected range:\n\n- `foiaxpress_public_access_link 11.13.1.0`","depth":"midnight","depthScore":54,"depthScoreParts":{"impact":53.9,"likelihood":0.1,"exploitation":0,"ransomware":0},"changes":[]}