ObjectPlanet kayıtları
objectplanet üreticisine ait 9 yayımlanmış kayıt.
Araştırmacı profili
- KEV’e giren
- 0 · %0
- Silahlaştırılmış
- 0 · %0
- Pre-auth RCE
- 1
- Düzeltme kaydı olan
- %0
- Yayından KEV’e ortanca
- KEV’e giren kayıt yok
Tekrar eden sınıflar
- CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')3
- CWE-335 Incorrect Usage of Seeds in Pseudo-Random Number Generator (PRNG)1
- CWE-352 Cross-Site Request Forgery (CSRF)1
- CWE-22 Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')1
- CWE-917 Improper Neutralization of Special Elements used in an Expression Language Statement ('Expression Language Injection')1
- CWE-918 Server-Side Request Forgery (SSRF)1
Bu üreticide en sık görülen zafiyet sınıfları: nereye bakmalı.
CWETüm kayıtlar
9 kayıt| Aksiyon | CVE | Zafiyet | Ciddiyet | KEV | EPSS | Yayın |
|---|---|---|---|---|---|---|
39İzleyin | CVE-2023-4472İstismar yok | Cryptographically weak PRNG in Opinio 7.22objectplanet · opinio · CWE-335 | Kritik9,8 | — | %0,7 | 1 Şub 2024 |
37İzleyin | CVE-2020-26806İstismar yok | admin/file.do in ObjectPlanet Opinio before 7.15 allows Unrestricted File Upload of executable JSP files, resulting in remote code executionobjectplanet · opinio · CWE-22 | Yüksek8,8 | — | %6,0 | 31 Tem 2021 |
31İzleyin | CVE-2020-26565İstismar yok | ObjectPlanet Opinio before 7.14 allows Expression Language Injection via the admin/permissionList.do from parameter.objectplanet · opinio · CWE-917 | Yüksek7,5 | — | %1,7 | 31 Tem 2021 |
26İzleyin | CVE-2020-26564İstismar yok | ObjectPlanet Opinio before 7.15 allows XXE attacks via three steps: modify a .css file to have <!ENTITY content, create a .xml file for a geobjectplanet · opinio · CWE-611 | Orta6,5 | — | %1,1 | 31 Tem 2021 |
24İzleyin | CVE-2020-26563İstismar yok | ObjectPlanet Opinio before 7.14 allows reflected XSS via the survey/admin/surveyAdmin.do?action=viewSurveyAdmin query string.objectplanet · opinio · CWE-79 | Orta6,1 | — | %1,0 | 30 Tem 2021 |
24İzleyin | CVE-2017-10798İstismar yok | In ObjectPlanet Opinio before 7.6.4, there is XSS.objectplanet · opinio · CWE-79 | Orta6,1 | — | %0,6 | 2 Tem 2017 |
19İzleyin | CVE-2025-13873İstismar yok | The feature to import a survey is prone to stored Cross-Site Script attacksobjectplanet · opinio · CWE-79 | Orta4,8 | — | %0,2 | 2 Ara 2025 |
9İzleyin | CVE-2025-13871İstismar yok | The feature to manage resources is prone to Cross-Site Request Forgery attacksobjectplanet · opinio · CWE-352 | Düşük2,3 | — | %0,2 | 2 Ara 2025 |
8İzleyin | CVE-2025-13872İstismar yok | Blind Server-Side Request Forgery (SSRF) in the survey-import feature of ObjectPlanet Opinioobjectplanet · opinio · CWE-918 | Düşük2,1 | — | %0,3 | 2 Ara 2025 |
- CVE-2023-447239İzleyin
Cryptographically weak PRNG in Opinio 7.22
KritikCVSS 9,8İstismar yokEPSS %1objectplanet · opinio1 Şub 2024
- CVE-2020-2680637İzleyin
admin/file.do in ObjectPlanet Opinio before 7.15 allows Unrestricted File Upload of executable JSP files, resulting in remote code execution
YüksekCVSS 8,8İstismar yokEPSS %6objectplanet · opinio31 Tem 2021
- CVE-2020-2656531İzleyin
ObjectPlanet Opinio before 7.14 allows Expression Language Injection via the admin/permissionList.do from parameter.
YüksekCVSS 7,5İstismar yokEPSS %2objectplanet · opinio31 Tem 2021
- CVE-2020-2656426İzleyin
ObjectPlanet Opinio before 7.15 allows XXE attacks via three steps: modify a .css file to have <!ENTITY content, create a .xml file for a ge
OrtaCVSS 6,5İstismar yokEPSS %1objectplanet · opinio31 Tem 2021
- CVE-2020-2656324İzleyin
ObjectPlanet Opinio before 7.14 allows reflected XSS via the survey/admin/surveyAdmin.do?action=viewSurveyAdmin query string.
OrtaCVSS 6,1İstismar yokEPSS %1objectplanet · opinio30 Tem 2021
- CVE-2017-1079824İzleyin
In ObjectPlanet Opinio before 7.6.4, there is XSS.
OrtaCVSS 6,1İstismar yokEPSS %1objectplanet · opinio2 Tem 2017
- CVE-2025-1387319İzleyin
The feature to import a survey is prone to stored Cross-Site Script attacks
OrtaCVSS 4,8İstismar yokEPSS %0objectplanet · opinio2 Ara 2025
- CVE-2025-138719İzleyin
The feature to manage resources is prone to Cross-Site Request Forgery attacks
DüşükCVSS 2,3İstismar yokEPSS %0objectplanet · opinio2 Ara 2025
- CVE-2025-138728İzleyin
Blind Server-Side Request Forgery (SSRF) in the survey-import feature of ObjectPlanet Opinio
DüşükCVSS 2,1İstismar yokEPSS %0objectplanet · opinio2 Ara 2025