Back to Database
Status published
High
CVE-2025-62586
OPEXUS FOIAXpress unauthenticated administrator password reset
Vulnerability Description
OPEXUS FOIAXpress allows a remote, unauthenticated attacker to reset the administrator password. Fixed in FOIAXpress version 11.13.2.0.
Impact Analysis
Refer to official advisory for detailed impact metrics.
Remediation
Ensure systems are updated to the latest vendor-supplied patch levels.
THREAT MONITOR
Am I Vulnerable?
Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2025-62586
Credits & Attribution
The following person or organization is credited with identifying this vulnerability, as recorded in the NVD database:
- Matthew Zamat, CISA
References
More from OPEXUS
View All →CVE-2025-61999
OPEXUS FOIAXpress stored XSS via logo image
Medium
4.8
CVE-2025-61998
OPEXUS FOIAXpress stored XSS via Hyperlink Manager
Medium
4.8
CVE-2025-61997
OPEXUS FOIAXpress stored XSS via banner image
Medium
4.8
CVE-2025-61996
OPEXUS FOIAXpress stored XSS via annual report template
Medium
4.8
CVE-2025-58462
OPEXUS FOIAXpress PAL SQL injection
Critical
9.3
Affected Vendor
OPEXUS
View all reports →Affected Software
FOIAXpress
Vulnerable Versions:
11.1.0, 11.13.2.0
Timeline
Official Publish:
October 16th, 2025
Last Modified:
February 26th, 2026
Added to House:
July 22nd, 2026
CVSS Vectors
V3:
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H