Search Results (2 CVEs found)

CVE Vendors Products Updated CVSS v3.1
CVE-2025-58462 2 Opexus, Opexustech 2 Foiaxpress Pal, Foiaxpress Public Access Link 2026-02-26 9.8 Critical
OPEXUS FOIAXpress Public Access Link (PAL) before version 11.13.1.0 allows SQL injection via SearchPopularDocs.aspx. A remote, unauthenticated attacker could read, write, or delete any content in the underlying database.
CVE-2025-62586 2 Opexus, Opexustech 2 Foiaxpress, Foiaxpress 2026-02-26 9.8 Critical
OPEXUS FOIAXpress allows a remote, unauthenticated attacker to reset the administrator password. Fixed in FOIAXpress version 11.13.2.0.