Cross-Site Request Forgery (CSRF) in the resource-management feature of
ObjectPlanet Opinio 7.26 rev12562
allows to upload
files on behalf of the connected users and then access such files without authentication.
ObjectPlanet Opinio 7.26 rev12562
allows to upload
files on behalf of the connected users and then access such files without authentication.
Metrics
Affected Vendors & Products
Advisories
No advisories yet.
Fixes
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
References
| Link | Providers |
|---|---|
| https://www.objectplanet.com/opinio/changelog.html |
|
History
Tue, 02 Dec 2025 10:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Cross-Site Request Forgery (CSRF) in the resource-management feature of ObjectPlanet Opinio 7.26 rev12562 allows to upload files on behalf of the connected users and then access such files without authentication. | |
| Title | The feature to manage resources is prone to Cross-Site Request Forgery attacks | |
| Weaknesses | CWE-352 | |
| References |
| |
| Metrics |
cvssV4_0
|
Status: PUBLISHED
Assigner: TCS-CERT
Published:
Updated: 2025-12-02T09:42:51.187Z
Reserved: 2025-12-02T09:16:58.809Z
Link: CVE-2025-13871
No data.
Status : Received
Published: 2025-12-02T10:16:01.687
Modified: 2025-12-02T10:16:01.687
Link: CVE-2025-13871
No data.
OpenCVE Enrichment
No data.