VendorsObjectPlanetopinioany version
Vulnerabilities

ObjectPlanet Opinio any version

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

6CVEs
CVE-2023-4472
Cryptographically weak PRNG in Opinio 7.22
Published 2024-02-01 · Modified
9.8EPSS 0.007
CVE-2020-26806
admin/file.do in ObjectPlanet Opinio before 7.15 allows Unrestricted File Upload of executable JSP files, resulting in remote code execution, because filePath can have directory traversal and fileContent can be valid JSP code.
Published 2021-07-31 · Modified
8.8EPSS 0.060
CVE-2020-26565
ObjectPlanet Opinio before 7.14 allows Expression Language Injection via the admin/permissionList.do from parameter. This can be used to retrieve possibly sensitive serverInfo data.
Published 2021-07-31 · Modified
7.5EPSS 0.017
CVE-2020-26564
ObjectPlanet Opinio before 7.15 allows XXE attacks via three steps: modify a .css file to have <!ENTITY content, create a .xml file for a generic survey template (containing a link to this .css file), and import this .xml file at the survey/admin/folderSurvey.do?action=viewImportSurvey['importFile'] URI. The XXE can then be triggered at a admin/preview.do?action=previewSurvey&surveyId= URI.
Published 2021-07-31 · Modified
6.5EPSS 0.011
CVE-2020-26563
ObjectPlanet Opinio before 7.14 allows reflected XSS via the survey/admin/surveyAdmin.do?action=viewSurveyAdmin query string. (There is also stored XSS if input to survey/admin/*.do is accepted from untrusted users.)
Published 2021-07-30 · Modified
6.1EPSS 0.010
CVE-2017-10798
In ObjectPlanet Opinio before 7.6.4, there is XSS.
Published 2017-07-03 · Modified
6.1EPSS 0.006