Stored Cross-Site Scripting (XSS) in the survey-import feature of ObjectPlanet Opinio 7.26 rev12562 on web application allows an attacker to inject arbitrary JavaScript code, which executes in the browsing context of any visitor accessing the compromised survey.
Metrics
Affected Vendors & Products
Advisories
No advisories yet.
Fixes
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
References
| Link | Providers |
|---|---|
| https://www.objectplanet.com/opinio/changelog.html |
|
History
Tue, 02 Dec 2025 10:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Stored Cross-Site Scripting (XSS) in the survey-import feature of ObjectPlanet Opinio 7.26 rev12562 on web application allows an attacker to inject arbitrary JavaScript code, which executes in the browsing context of any visitor accessing the compromised survey. | |
| Title | The feature to import a survey is prone to stored Cross-Site Script attacks | |
| First Time appeared |
Objectplanet
Objectplanet opinio |
|
| Weaknesses | CWE-79 | |
| CPEs | cpe:2.3:a:objectplanet:opinio:7.26_rev12562:*:*:*:*:*:*:* | |
| Vendors & Products |
Objectplanet
Objectplanet opinio |
|
| References |
| |
| Metrics |
cvssV4_0
|
Status: PUBLISHED
Assigner: TCS-CERT
Published:
Updated: 2025-12-02T09:56:16.762Z
Reserved: 2025-12-02T09:17:07.251Z
Link: CVE-2025-13873
No data.
Status : Received
Published: 2025-12-02T10:16:02.073
Modified: 2025-12-02T10:16:02.073
Link: CVE-2025-13873
No data.
OpenCVE Enrichment
No data.