CVE-2025-13871

HIGH

Objectplanet Opinio - CSRF

Title source: rule

Description

Cross-Site Request Forgery (CSRF) in the resource-management feature of ObjectPlanet Opinio 7.26 rev12562 allows to upload files on behalf of the connected users and then access such files without authentication.

Scores

CVSS v3 8.8
EPSS 0.0003
EPSS Percentile 7.9%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H

Classification

CWE
CWE-352
Status published

Affected Products (1)

objectplanet/opinio

Timeline

Published Dec 02, 2025
Tracked Since Feb 18, 2026