CVE-2025-13871
Severity CVSS v4.0:
LOW
Type:
CWE-352
Cross-Site Request Forgery (CSRF)
Publication date:
02/12/2025
Last modified:
04/12/2025
Description
Cross-Site Request Forgery (CSRF) in the resource-management feature of <br />
<br />
ObjectPlanet Opinio 7.26 rev12562<br />
<br />
allows to upload <br />
files on behalf of the connected users and then access such files without authentication.
Impact
Base Score 4.0
2.30
Severity 4.0
LOW
Base Score 3.x
8.80
Severity 3.x
HIGH
Vulnerable products and versions
| CPE | From | Up to |
|---|---|---|
| cpe:2.3:a:objectplanet:opinio:7.26:*:*:*:*:*:*:* |
To consult the complete list of CPE names with products and versions, see this page



