OPEXUS FOIAXpress Public Access Link
cpe:2.3:a:ains:foiaxpress:*:*:*:*:*:*:*
- < 11.13.1.0
A SQL injection vulnerability has been identified in OPEXUS FOIAXpress Public Access Link (PAL) versions prior to 11.13.1.0. The vulnerability allows remote, unauthenticated attackers to read, write, or delete any content in the underlying database via the SearchPopularDocs.aspx page.
Exploitation of this vulnerability allows for arbitrary SQL injection, enabling attackers to manipulate the database in various ways, including reading, writing, or deleting data.
Users can update to OPEXUS FOIAXpress version 11.13.1.0 or later to address this vulnerability.
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.