2.1
/ 10
LOW
CVSS:4.0/AV:N/AC:H/AT:P/PR:H/UI:N/VC:N/VI:N/VA:N/SC:L/SI:N/SA:N
Description
Blind Server-Side Request Forgery (SSRF) in the survey-import feature of
ObjectPlanet Opinio 7.26 rev12562 on
Web-based platforms allows an attacker to force the server to perform HTTP GET requests via crafted import requests
to an arbitrary destination.
ObjectPlanet Opinio 7.26 rev12562 on
Web-based platforms allows an attacker to force the server to perform HTTP GET requests via crafted import requests
to an arbitrary destination.
Basic Information
ID
CVE-2025-13872
Source
TCS-CERT
Published
Dec 2, 2025 at 09:51
Affected Product
Vendor
ObjectPlanet
Product
Opinio
Version
7.26 rev12562
Affected Versions
ObjectPlanet Opinio 7.26 rev12562