CVE 2.1 LOW

Blind Server-Side Request Forgery (SSRF) in the survey-import feature of ObjectPlanet Opinio_CVE-2025-13872

2.1 / 10
LOW
CVSS:4.0/AV:N/AC:H/AT:P/PR:H/UI:N/VC:N/VI:N/VA:N/SC:L/SI:N/SA:N

Description

Blind Server-Side Request Forgery (SSRF) in the survey-import feature of

ObjectPlanet Opinio 7.26 rev12562 on

Web-based platforms allows an attacker to force the server to perform HTTP GET requests via crafted import requests

to an arbitrary destination.

Basic Information

ID CVE-2025-13872
Source TCS-CERT
Published Dec 2, 2025 at 09:51

Affected Product

Vendor ObjectPlanet
Product Opinio
Version 7.26 rev12562
Affected Versions ObjectPlanet Opinio 7.26 rev12562

CWE Classification

References

💭 Join the Security Discussion

🔒 Your email address will not be published. Required fields are marked *

⚠️ Please be respectful and constructive in your comments. Security discussions should remain professional.