Show filters
6 Total Results
Displaying 1-6 of 6
Sort by:
Attacker Value
Unknown

CVE-2023-4472

Disclosure Date: February 01, 2024 (last updated February 10, 2024)
Objectplanet Opinio version 7.22 and prior uses a cryptographically weak pseudo-random number generator (PRNG) coupled to a predictable seed, which could lead to an unauthenticated account takeover of any user on the application.
Attacker Value
Unknown

CVE-2020-26565

Disclosure Date: July 31, 2021 (last updated February 23, 2025)
ObjectPlanet Opinio before 7.14 allows Expression Language Injection via the admin/permissionList.do from parameter. This can be used to retrieve possibly sensitive serverInfo data.
Attacker Value
Unknown

CVE-2020-26564

Disclosure Date: July 31, 2021 (last updated February 23, 2025)
ObjectPlanet Opinio before 7.15 allows XXE attacks via three steps: modify a .css file to have <!ENTITY content, create a .xml file for a generic survey template (containing a link to this .css file), and import this .xml file at the survey/admin/folderSurvey.do?action=viewImportSurvey['importFile'] URI. The XXE can then be triggered at a admin/preview.do?action=previewSurvey&surveyId= URI.
Attacker Value
Unknown

CVE-2020-26806

Disclosure Date: July 31, 2021 (last updated February 23, 2025)
admin/file.do in ObjectPlanet Opinio before 7.15 allows Unrestricted File Upload of executable JSP files, resulting in remote code execution, because filePath can have directory traversal and fileContent can be valid JSP code.
Attacker Value
Unknown

CVE-2020-26563

Disclosure Date: July 30, 2021 (last updated February 23, 2025)
ObjectPlanet Opinio before 7.14 allows reflected XSS via the survey/admin/surveyAdmin.do?action=viewSurveyAdmin query string. (There is also stored XSS if input to survey/admin/*.do is accepted from untrusted users.)
Attacker Value
Unknown

CVE-2017-10798

Disclosure Date: July 03, 2017 (last updated November 26, 2024)
In ObjectPlanet Opinio before 7.6.4, there is XSS.
0