Show filters
6 Total Results
Displaying 1-6 of 6
Sort by:
Attacker Value
Unknown
CVE-2023-4472
Disclosure Date: February 01, 2024 (last updated February 10, 2024)
Objectplanet Opinio version 7.22 and prior uses a cryptographically weak pseudo-random number generator (PRNG) coupled to a predictable seed, which could lead to an unauthenticated account takeover of any user on the application.
0
Attacker Value
Unknown
CVE-2020-26565
Disclosure Date: July 31, 2021 (last updated February 23, 2025)
ObjectPlanet Opinio before 7.14 allows Expression Language Injection via the admin/permissionList.do from parameter. This can be used to retrieve possibly sensitive serverInfo data.
0
Attacker Value
Unknown
CVE-2020-26564
Disclosure Date: July 31, 2021 (last updated February 23, 2025)
ObjectPlanet Opinio before 7.15 allows XXE attacks via three steps: modify a .css file to have <!ENTITY content, create a .xml file for a generic survey template (containing a link to this .css file), and import this .xml file at the survey/admin/folderSurvey.do?action=viewImportSurvey['importFile'] URI. The XXE can then be triggered at a admin/preview.do?action=previewSurvey&surveyId= URI.
0
Attacker Value
Unknown
CVE-2020-26806
Disclosure Date: July 31, 2021 (last updated February 23, 2025)
admin/file.do in ObjectPlanet Opinio before 7.15 allows Unrestricted File Upload of executable JSP files, resulting in remote code execution, because filePath can have directory traversal and fileContent can be valid JSP code.
0
Attacker Value
Unknown
CVE-2020-26563
Disclosure Date: July 30, 2021 (last updated February 23, 2025)
ObjectPlanet Opinio before 7.14 allows reflected XSS via the survey/admin/surveyAdmin.do?action=viewSurveyAdmin query string. (There is also stored XSS if input to survey/admin/*.do is accepted from untrusted users.)
0
Attacker Value
Unknown
CVE-2017-10798
Disclosure Date: July 03, 2017 (last updated November 26, 2024)
In ObjectPlanet Opinio before 7.6.4, there is XSS.
0