CVE-2025-54834

OPEXUS FOIAXpress Public Access Link (PAL) version v11.1.0 allows an unauthenticated, remote attacker to query the /App/CreateRequest.aspx endpoint to check for the existence of valid usernames. There are no rate-limiting mechanisms in place.
Configurations

No configuration.

History

31 Jul 2025, 18:15

Type Values Removed Values Added
New CVE

Information

Published : 2025-07-31 18:15

Updated : 2025-07-31 18:42


NVD link : CVE-2025-54834

Mitre link : CVE-2025-54834

CVE.ORG link : CVE-2025-54834


JSON object : View

Products Affected

No product.

CWE
CWE-204

Observable Response Discrepancy