Skip to content
Noroxi

ObjectPlanet records

9 published records for vendor objectplanet.

All records

9 records
  • CVE-2023-4472
    39Monitor

    Cryptographically weak PRNG in Opinio 7.22

    CriticalCVSS 9.8No exploitEPSS 1%

    objectplanet · opinioFeb 1, 2024

  • admin/file.do in ObjectPlanet Opinio before 7.15 allows Unrestricted File Upload of executable JSP files, resulting in remote code execution

    HighCVSS 8.8No exploitEPSS 6%

    objectplanet · opinioJul 31, 2021

  • ObjectPlanet Opinio before 7.14 allows Expression Language Injection via the admin/permissionList.do from parameter.

    HighCVSS 7.5No exploitEPSS 2%

    objectplanet · opinioJul 31, 2021

  • ObjectPlanet Opinio before 7.15 allows XXE attacks via three steps: modify a .css file to have <!ENTITY content, create a .xml file for a ge

    MediumCVSS 6.5No exploitEPSS 1%

    objectplanet · opinioJul 31, 2021

  • ObjectPlanet Opinio before 7.14 allows reflected XSS via the survey/admin/surveyAdmin.do?action=viewSurveyAdmin query string.

    MediumCVSS 6.1No exploitEPSS 1%

    objectplanet · opinioJul 30, 2021

  • In ObjectPlanet Opinio before 7.6.4, there is XSS.

    MediumCVSS 6.1No exploitEPSS 1%

    objectplanet · opinioJul 2, 2017

  • The feature to import a survey is prone to stored Cross-Site Script attacks

    MediumCVSS 4.8No exploitEPSS 0%

    objectplanet · opinioDec 2, 2025

  • The feature to manage resources is prone to Cross-Site Request Forgery attacks

    LowCVSS 2.3No exploitEPSS 0%

    objectplanet · opinioDec 2, 2025

  • Blind Server-Side Request Forgery (SSRF) in the survey-import feature of ObjectPlanet Opinio

    LowCVSS 2.1No exploitEPSS 0%

    objectplanet · opinioDec 2, 2025