Stored Cross-Site Scripting (XSS) in the survey-import feature of ObjectPlanet Opinio 7.26 rev12562 on web application allows an attacker to inject arbitrary JavaScript code, which executes in the browsing context of any visitor accessing the compromised survey.
Advisories

No advisories yet.

Fixes

Solution

No solution given by the vendor.


Workaround

No workaround given by the vendor.

History

Tue, 02 Dec 2025 10:00:00 +0000

Type Values Removed Values Added
Description Stored Cross-Site Scripting (XSS) in the survey-import feature of ObjectPlanet Opinio 7.26 rev12562 on web application allows an attacker to inject arbitrary JavaScript code, which executes in the browsing context of any visitor accessing the compromised survey.
Title The feature to import a survey is prone to stored Cross-Site Script attacks
First Time appeared Objectplanet
Objectplanet opinio
Weaknesses CWE-79
CPEs cpe:2.3:a:objectplanet:opinio:7.26_rev12562:*:*:*:*:*:*:*
Vendors & Products Objectplanet
Objectplanet opinio
References
Metrics cvssV4_0

{'score': 4.8, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:P/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N'}


cve-icon MITRE

Status: PUBLISHED

Assigner: TCS-CERT

Published:

Updated: 2025-12-02T09:56:16.762Z

Reserved: 2025-12-02T09:17:07.251Z

Link: CVE-2025-13873

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2025-12-02T10:16:02.073

Modified: 2025-12-02T10:16:02.073

Link: CVE-2025-13873

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

No data.