CVE-2020-26563

Severity CVSS v4.0:
Pending analysis
Type:
CWE-79 Cross-Site Scripting (XSS)
Publication date:
30/07/2021
Last modified:
02/08/2021

Description

ObjectPlanet Opinio before 7.14 allows reflected XSS via the survey/admin/surveyAdmin.do?action=viewSurveyAdmin query string. (There is also stored XSS if input to survey/admin/*.do is accepted from untrusted users.)

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:objectplanet:opinio:*:*:*:*:*:*:*:* 7.13 (excluding)