CVE-2025-13872

Blind Server-Side Request Forgery (SSRF) in the survey-import feature of ObjectPlanet Opinio 7.26 rev12562 on Web-based platforms allows an attacker to force the server to perform HTTP GET requests via crafted import requests to an arbitrary destination.
CVSS

No CVSS.

Configurations

No configuration.

History

02 Dec 2025, 10:16

Type Values Removed Values Added
New CVE

Information

Published : 2025-12-02 10:16

Updated : 2025-12-02 17:16


NVD link : CVE-2025-13872

Mitre link : CVE-2025-13872

CVE.ORG link : CVE-2025-13872


JSON object : View

Products Affected

No product.

CWE
CWE-918

Server-Side Request Forgery (SSRF)