ObjectPlanet Opinio 7.26 rev12562 on
Web-based platforms allows an attacker to force the server to perform HTTP GET requests via crafted import requests
to an arbitrary destination.
No advisories yet.
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
| Link | Providers |
|---|---|
| https://www.objectplanet.com/opinio/changelog.html |
|
Thu, 04 Dec 2025 18:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| CPEs | cpe:2.3:a:objectplanet:opinio:7.26:*:*:*:*:*:*:* | |
| Metrics |
cvssV3_1
|
Tue, 02 Dec 2025 17:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Tue, 02 Dec 2025 10:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Blind Server-Side Request Forgery (SSRF) in the survey-import feature of ObjectPlanet Opinio 7.26 rev12562 on Web-based platforms allows an attacker to force the server to perform HTTP GET requests via crafted import requests to an arbitrary destination. | |
| Title | Blind Server-Side Request Forgery (SSRF) in the survey-import feature of ObjectPlanet Opinio | |
| First Time appeared |
Objectplanet
Objectplanet opinio |
|
| Weaknesses | CWE-918 | |
| CPEs | cpe:2.3:a:objectplanet:opinio:7.26_rev12562:*:*:*:*:*:*:* | |
| Vendors & Products |
Objectplanet
Objectplanet opinio |
|
| References |
| |
| Metrics |
cvssV4_0
|
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: TCS-CERT
Published:
Updated: 2025-12-02T16:55:02.348Z
Reserved: 2025-12-02T09:17:04.605Z
Link: CVE-2025-13872
Updated: 2025-12-02T16:50:33.197Z
Status : Analyzed
Published: 2025-12-02T10:16:01.877
Modified: 2025-12-04T17:52:30.360
Link: CVE-2025-13872
No data.
OpenCVE Enrichment
No data.