Stored Cross-Site Scripting (XSS) in the survey-import feature of ObjectPlanet Opinio 7.26 rev12562 on web application allows an attacker to inject arbitrary JavaScript code, which executes in the browsing context of any visitor accessing the compromised survey.
Advisories

No advisories yet.

Fixes

Solution

No solution given by the vendor.


Workaround

No workaround given by the vendor.

History

Fri, 05 Dec 2025 03:00:00 +0900

Type Values Removed Values Added
CPEs cpe:2.3:a:objectplanet:opinio:7.26:*:*:*:*:*:*:*
Metrics cvssV3_1

{'score': 5.4, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N'}


Wed, 03 Dec 2025 02:15:00 +0900

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Tue, 02 Dec 2025 19:00:00 +0900

Type Values Removed Values Added
Description Stored Cross-Site Scripting (XSS) in the survey-import feature of ObjectPlanet Opinio 7.26 rev12562 on web application allows an attacker to inject arbitrary JavaScript code, which executes in the browsing context of any visitor accessing the compromised survey.
Title The feature to import a survey is prone to stored Cross-Site Script attacks
First Time appeared Objectplanet
Objectplanet opinio
Weaknesses CWE-79
CPEs cpe:2.3:a:objectplanet:opinio:7.26_rev12562:*:*:*:*:*:*:*
Vendors & Products Objectplanet
Objectplanet opinio
References
Metrics cvssV4_0

{'score': 4.8, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:P/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N'}


Projects

Sign in to view the affected projects.

cve-icon MITRE

Status: PUBLISHED

Assigner: TCS-CERT

Published:

Updated: 2025-12-02T16:54:53.196Z

Reserved: 2025-12-02T09:17:07.251Z

Link: CVE-2025-13873

cve-icon Vulnrichment

Updated: 2025-12-02T16:50:30.961Z

cve-icon NVD

Status : Analyzed

Published: 2025-12-02T10:16:02.073

Modified: 2025-12-04T17:49:40.143

Link: CVE-2025-13873

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

No data.

Weaknesses