Stored Cross-Site Scripting (XSS) in the survey-import feature of ObjectPlanet Opinio 7.26 rev12562 on web application allows an attacker to inject arbitrary JavaScript code, which executes in the browsing context of any visitor accessing the compromised survey.
History

Thu, 04 Dec 2025 18:00:00 +0000

Type Values Removed Values Added
CPEs cpe:2.3:a:objectplanet:opinio:7.26:*:*:*:*:*:*:*
Metrics cvssV3_1

{'score': 5.4, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N'}


Tue, 02 Dec 2025 17:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Tue, 02 Dec 2025 10:00:00 +0000

Type Values Removed Values Added
Description Stored Cross-Site Scripting (XSS) in the survey-import feature of ObjectPlanet Opinio 7.26 rev12562 on web application allows an attacker to inject arbitrary JavaScript code, which executes in the browsing context of any visitor accessing the compromised survey.
Title The feature to import a survey is prone to stored Cross-Site Script attacks
First Time appeared Objectplanet
Objectplanet opinio
Weaknesses CWE-79
CPEs cpe:2.3:a:objectplanet:opinio:7.26_rev12562:*:*:*:*:*:*:*
Vendors & Products Objectplanet
Objectplanet opinio
References
Metrics cvssV4_0

{'score': 4.8, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:P/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N'}


cve-icon MITRE

Status: PUBLISHED

Assigner: TCS-CERT

Published: 2025-12-02T09:56:16.762Z

Updated: 2025-12-02T16:54:53.196Z

Reserved: 2025-12-02T09:17:07.251Z

Link: CVE-2025-13873

cve-icon Vulnrichment

Updated: 2025-12-02T16:50:30.961Z

cve-icon NVD

Status : Analyzed

Published: 2025-12-02T10:16:02.073

Modified: 2025-12-04T17:49:40.143

Link: CVE-2025-13873

cve-icon Redhat

No data.