The feature to import a survey is prone to stored Cross-Site Script attacks
Vulnerability Description
Stored Cross-Site Scripting (XSS) in the survey-import feature of ObjectPlanet Opinio 7.26 rev12562 on web application allows an attacker to inject arbitrary JavaScript code, which executes in the browsing context of any visitor accessing the compromised survey.
Impact Analysis
Refer to official advisory for detailed impact metrics.
Remediation
Ensure systems are updated to the latest vendor-supplied patch levels.
Am I Vulnerable?
Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2025-13873
Credits & Attribution
The following person or organization is credited with identifying this vulnerability, as recorded in the NVD database:
- Dominique Righetto
Affected Vendor
ObjectPlanet
View all reports →