CNNVD-202512-261 Information

CNNVD ID

CNNVD-202512-261

CVE-2025-13872

  • CNNVD Published: 2025-12-02

Description (Chinese)

ObjectPlanet Opinio是挪威ObjectPlanet公司的一个在线调查系统。 ObjectPlanet Opinio 7.26 rev12562版本存在安全漏洞,该漏洞源于调查导入功能存在盲服务端请求伪造,可能导致服务器执行任意HTTP GET请求。

Description (English)

ObjectPlanet Opinio is an online investigation system of ObjectPlant, Norway. There is a security loophole in the version 7.26 rev12562 of ObjectPlanet Opinio, which stems from the existence of blind service requests for forgery in the investigative import function, which may result in the server executing an arbitrary HTTP GET request.

Hazard Level

High

Vulnerability Type

其他

Affected Vendor

ObjectPlanet

Published

2025-12-02

Last Modified

2026-02-24

References

https://www.objectplanet.com/opinio/changelog.html

Patch

https://www.objectplanet.com/

Share on: