Vulnerabilities (CVE)

Filtered by vendor Objectplanet Subscribe
Filtered by product Opinio
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2020-26564 1 Objectplanet 1 Opinio 2021-08-09 4.0 MEDIUM 6.5 MEDIUM
ObjectPlanet Opinio before 7.15 allows XXE attacks via three steps: modify a .css file to have <!ENTITY content, create a .xml file for a generic survey template (containing a link to this .css file), and import this .xml file at the survey/admin/folderSurvey.do?action=viewImportSurvey['importFile'] URI. The XXE can then be triggered at a admin/preview.do?action=previewSurvey&surveyId= URI.
CVE-2020-26563 1 Objectplanet 1 Opinio 2021-08-02 4.3 MEDIUM 6.1 MEDIUM
ObjectPlanet Opinio before 7.14 allows reflected XSS via the survey/admin/surveyAdmin.do?action=viewSurveyAdmin query string. (There is also stored XSS if input to survey/admin/*.do is accepted from untrusted users.)
CVE-2017-10798 1 Objectplanet 1 Opinio 2017-07-05 4.3 MEDIUM 6.1 MEDIUM
In ObjectPlanet Opinio before 7.6.4, there is XSS.