External risk intelligence

OPEXUS FOIAXpress PAL SQL Injection Vulnerability

CVE advisorySeverity: CRITICAL (CVSS 9.3)

CVE-2025-58462

The product, FOIAXpress Public Access Link (PAL), is designed specifically to provide a public-facing portal for external users to interact with government records. As an internet-facing web application intended for unauthenticated public access, the vulnerable endpoint is exposed by design in normal deployments.

SQL Injection

Opexustech Foiaxpress Public Access Link

before 11.13.1.0

Halo Surface Signal: 5 out of 5 — more likely to be public-facing.

External exposure likelihood

Horizon Alert

Summary of the vulnerability and why it matters

This vulnerability affects the OPEXUS FOIAXpress Public Access Link, a system that allows public access to information. The issue could permit unauthorized individuals to view, alter, or remove data stored within the system's database without needing any credentials.

  • Public access system allows data tampering.
  • Critical, unauthenticated access to sensitive data.
  • Confirm if this public-facing data system is in use.

Attack Path

How an attacker could exploit the issue

An attacker can leverage the SQL injection vulnerability in OPEXUS FOIAXpress Public Access Link's SearchPopularDocs.aspx feature to interact with the system's database. This attack can be initiated remotely without requiring any authentication, allowing the attacker to potentially access, modify, or delete sensitive information stored within the database.

  • No authentication needed to access.
  • SearchPopularDocs.aspx triggers vulnerability.
  • Full database access and modification.

Live Threat

Current exploitation, exposure, and threat context

A remote, unauthenticated attacker could exploit a SQL injection vulnerability in OPEXUS FOIAXpress Public Access Link (PAL) via SearchPopularDocs.aspx. This could allow them to read, write, or delete any content within the underlying database.

  • Database content at risk.
  • SQL injection via a public web endpoint.
  • Unauthorized data access and manipulation.

Operational Fix

Recommended remediation, mitigation, and detection steps

Application owners and infrastructure teams are likely responsible for addressing this SQL injection vulnerability in the OPEXUS FOIAXpress Public Access Link. The first practical step involves identifying all instances of the affected technology, confirming its network reachability and business criticality, and then locating the accountable owner to initiate a risk-based remediation plan.

  • Application owners should own the issue.
  • Verify external reachability and business criticality.
  • Plan remediation based on exposure and impact.

Supplementary metadata

Validate whether this threat affects your internet-facing exposure.

Halo Threat Intelligence helps prioritize remediation with Halo Surface Signal and H/A/L/O context. Start exposure validation with a free external attack surface trial.

Frequently asked questions

What is OPEXUS FOIAXpress Public Access Link?

FOIAXpress Public Access Link (PAL) is a specialized web portal used by government agencies to manage Freedom of Information Act requests. It provides a structured interface allowing members of the public to search for, submit, and track records electronically. Because it acts as a bridge between public users and internal government record systems, it is inherently designed to be accessible over the internet.

What does SQL injection mean for CVE-2025-58462?

This vulnerability falls under the CWE-89 weakness class, which happens when an application fails to properly sanitize user input before including it in a database query. In this specific case, the flaw allows an attacker to inject their own malicious commands into the system's database. This grants them the ability to bypass typical security checks to view, change, or delete the stored records that the application manages.

How is the CVE-2025-58462 vulnerability triggered?

The flaw is triggered by sending specially crafted input to the SearchPopularDocs.aspx page within the application. Because the system does not require authentication, an attacker does not need a user account or login credentials to initiate this request. Simply interacting with this specific search function via a standard web browser or automated tool is sufficient to trigger the underlying database manipulation.

Why is this CVE high-risk for my organization?

Halo Surface Signal notes that this product is intended for public-facing use, meaning it is almost always deployed with internet-facing access. Since the vulnerability requires no authentication and targets the core database, the lack of a barrier between an anonymous internet user and your sensitive government records makes this a significant concern for any organization running an unpatched version of the PAL software.

What are the first steps to address this threat?

Your initial priority should be to inventory all active instances of the FOIAXpress Public Access Link in your environment to determine which systems are reachable from the internet. Once you have identified these assets, verify their current version against the vendor's update documentation. Coordinate with your application administrators to schedule and apply the necessary software updates provided by OPEXUS to secure the affected search functionality.

References