Executive brief
ObjectPlanet Opinio is a web-based survey and feedback platform used by organizations to collect and analyze customer and employee responses. A blind server-side request forgery vulnerability in the survey import feature allows an attacker to force the server to perform HTTP requests to arbitrary destinations, potentially enabling reconnaissance of internal network resources, theft of sensitive data from internal systems, or attacks against third-party services.
Technical details
This is a blind server-side request forgery (SSRF) vulnerability in the survey-import feature of ObjectPlanet Opinio 7.26 rev12562. The vulnerability allows an attacker to craft malicious import requests that cause the server to perform HTTP GET requests to arbitrary destinations without proper validation or sanitization. The attack does not require authentication or user interaction beyond uploading a crafted survey import file. An attacker can exploit this to access internal network resources, retrieve sensitive data from internal systems, or launch attacks against third-party services from the server's perspective. The vulnerability has been patched in Opinio 7.27 (released July 31, 2025) and subsequent versions.
Affected products
- ObjectPlanet Opinio 7.26 rev12562 and earlier
Timeline
- 2025-12-02: disclosed
- 2025-07-31: patched: Fixed in Opinio 7.27