2.3
/ 10
LOW
CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:P/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N
Description
Cross-Site Request Forgery (CSRF) in the resource-management feature of
ObjectPlanet Opinio 7.26 rev12562
allows to upload
files on behalf of the connected users and then access such files without authentication.
ObjectPlanet Opinio 7.26 rev12562
allows to upload
files on behalf of the connected users and then access such files without authentication.
Basic Information
ID
CVE-2025-13871
Source
TCS-CERT
Published
Dec 2, 2025 at 09:42
Affected Product
Vendor
ObjectPlanet
Product
Opinio
Version
7.26 rev12562
Affected Versions
ObjectPlanet Opinio 7.26 rev12562