CVE-2025-13871
HIGHObjectplanet Opinio - CSRF
Title source: ruleDescription
Cross-Site Request Forgery (CSRF) in the resource-management feature of ObjectPlanet Opinio 7.26 rev12562 allows to upload files on behalf of the connected users and then access such files without authentication.
Scores
CVSS v3
8.8
EPSS
0.0003
EPSS Percentile
7.9%
Attack Vector
NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
Classification
CWE
CWE-352
Status
published
Affected Products (1)
objectplanet/opinio
Timeline
Published
Dec 02, 2025
Tracked Since
Feb 18, 2026