CVE Browser
The feature to import a survey is prone to stored Cross-Site Script attacks
Blind Server-Side Request Forgery (SSRF) in the survey-import feature of ObjectPlanet Opinio
The feature to manage resources is prone to Cross-Site Request Forgery attacks
Cryptographically weak PRNG in Opinio 7.22
ObjectPlanet Opinio before 7.14 allows Expression Language Injection via the admin/permissionList.do from parameter. This can be used to retrieve possibly sens…
ObjectPlanet Opinio before 7.15 allows XXE attacks via three steps: modify a .css file to have <!ENTITY content, create a .xml file for a generic survey templa…
admin/file.do in ObjectPlanet Opinio before 7.15 allows Unrestricted File Upload of executable JSP files, resulting in remote code execution, because filePath…
ObjectPlanet Opinio before 7.14 allows reflected XSS via the survey/admin/surveyAdmin.do?action=viewSurveyAdmin query string. (There is also stored XSS if inpu…
In ObjectPlanet Opinio before 7.6.4, there is XSS.
Showing 1 to 9 CVEs · page 1