Authentication Bypass in OPEXUS FOIAXpress Public Access Link
CVE-2025-54832

5.3MEDIUM

Key Information:

Vendor

Opexus

Vendor
CVE Published:
31 July 2025

What is CVE-2025-54832?

The OPEXUS FOIAXpress Public Access Link (PAL) is vulnerable to an authentication bypass issue in version v11.1.0. This vulnerability allows authenticated users to improperly add entries to the list of states and territories, potentially leading to unauthorized access and data integrity issues. Users are urged to update to a patched version to ensure the security of their applications.

Affected Version(s)

FOIAXpress Public Access Link (PAL) 11.1.0 < 11.12.3.0

FOIAXpress Public Access Link (PAL) 11.12.3.0

References

CVSS V4

Score:
5.3
Severity:
MEDIUM
Confidentiality:
None
Integrity:
Low
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Nathan Spidle, CISA
.
CVE-2025-54832 : Authentication Bypass in OPEXUS FOIAXpress Public Access Link