The feature to import a survey is prone to stored Cross-Site Script attacks
Summary
| CVE | CVE-2025-13873 |
|---|---|
| State | PUBLISHED |
| Assigner | TCS-CERT |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2025-12-02 10:16:02 UTC |
| Updated | 2026-09-03 03:15:24 UTC |
| Description | Stored Cross-Site Scripting (XSS) in the survey-import feature of ObjectPlanet Opinio 7.26 rev12562 on web application allows an attacker to inject arbitrary JavaScript code, which executes in the browsing context of any visitor accessing the compromised survey. |
Risk And Classification
Primary CVSS: v4.0 4.8 MEDIUM from 64c5ae8f-7972-4697-86a0-7ada793ac795
CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:P/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
Problem Types: CWE-79 | CWE-79 CWE-79 Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting')
| Version | Source | Type | Score | Severity | Vector |
|---|---|---|---|---|---|
| 4.0 | 64c5ae8f-7972-4697-86a0-7ada793ac795 | Secondary | 4.8 | MEDIUM | CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:P/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N/E:X/C... |
| 4.0 | CNA | CVSS | 4.8 | MEDIUM | CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:P/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N |
| 3.1 | [email protected] | Primary | 5.4 | MEDIUM | CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N |
CVSS v4.0 Breakdown
Attack Vector
NetworkAttack Complexity
LowAttack Requirements
NonePrivileges Required
HighUser Interaction
PassiveConfidentiality
LowIntegrity
LowAvailability
NoneSub Conf.
NoneSub Integrity
NoneSub Availability
NoneCVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:P/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
CVSS v3.1 Breakdown
Attack Vector
NetworkAttack Complexity
LowPrivileges Required
LowUser Interaction
RequiredScope
ChangedConfidentiality
LowIntegrity
LowAvailability
NoneCVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Application | Objectplanet | Opinio | 7.26 | All | All | All |
Vendor Declared Affected Products
| Source | Vendor | Product | Version | Platforms |
|---|---|---|---|---|
| CNA | ObjectPlanet | Opinio | affected 7.26 rev12562 | Not specified |
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| www.objectplanet.com/opinio/changelog.html | 64c5ae8f-7972-4697-86a0-7ada793ac795 | www.objectplanet.com | Release Notes |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
Vendor Comments And Credit
Discovery Credit
CNA: Dominique Righetto (en)
Additional Advisory Data
| Source | Time | Event |
|---|---|---|
| CNA | 2024-12-01T09:10:00.000Z | Vulnerability discovery |
| CNA | 2024-12-10T14:22:00.000Z | Vulnerability Report to TCS-CERT |
| CNA | 2024-12-19T15:33:00.000Z | Vulnerability Report to Vendor through email : [email protected] |
| CNA | 2024-12-24T15:34:00.000Z | Feedback asked to vendor, check if the vendor received the PoC in an encrypted archive |
| CNA | 2025-01-10T15:32:00.000Z | New follow-up email was send to the vendor |
| CNA | 2025-01-13T15:37:00.000Z | Vendor confirmed the reception of the PoC, vendor asked to wait 90-day period before publishing (responsible disclosure), and will try to fix the vulnerability |
| CNA | 2025-01-14T15:37:00.000Z | Answer to vendor to acknowledge 90 days period |
| CNA | 2025-03-10T15:38:00.000Z | Vendor informed us that they will realse the fix by the end of this month |
| CNA | 2025-04-23T14:39:00.000Z | An email was sent to check where they stand on the release and fixes for the reported issues |
| CNA | 2025-06-21T14:39:00.000Z | A feedback was requested from vendor regarding their progreess |
| CNA | 2025-06-30T14:39:00.000Z | A feedback was requested from vendor regarding their progreess |
| CNA | 2025-07-31T14:39:00.000Z | The vendor released the newer fixed version which is the Opinio Version 7.27 |
There are currently no legacy QID mappings associated with this CVE.