ObjectPlanet Opinio 7.26 rev12562
allows to upload
files on behalf of the connected users and then access such files without authentication.
No advisories yet.
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
| Link | Providers |
|---|---|
| https://www.objectplanet.com/opinio/changelog.html |
|
Thu, 04 Dec 2025 18:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| CPEs | cpe:2.3:a:objectplanet:opinio:7.26:*:*:*:*:*:*:* | |
| Metrics |
cvssV3_1
|
Wed, 03 Dec 2025 12:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Objectplanet
Objectplanet opinio |
|
| Vendors & Products |
Objectplanet
Objectplanet opinio |
Tue, 02 Dec 2025 17:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Tue, 02 Dec 2025 10:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Cross-Site Request Forgery (CSRF) in the resource-management feature of ObjectPlanet Opinio 7.26 rev12562 allows to upload files on behalf of the connected users and then access such files without authentication. | |
| Title | The feature to manage resources is prone to Cross-Site Request Forgery attacks | |
| Weaknesses | CWE-352 | |
| References |
| |
| Metrics |
cvssV4_0
|
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: TCS-CERT
Published:
Updated: 2025-12-02T16:55:09.792Z
Reserved: 2025-12-02T09:16:58.809Z
Link: CVE-2025-13871
Updated: 2025-12-02T16:50:35.658Z
Status : Analyzed
Published: 2025-12-02T10:16:01.687
Modified: 2025-12-04T17:54:28.767
Link: CVE-2025-13871
No data.
OpenCVE Enrichment
Updated: 2025-12-03T12:10:10Z