Junglewise Threat Intelligence

CVE-2025-13872: ObjectPlanet Opinio blind server-side request forgery in survey import

CVE-2025-13872 · Severity: critical · CVSS 9.1 · Published 2025-12-02

Technologies: Objectplanet Opinio. Vendors: Objectplanet.

Executive brief

ObjectPlanet Opinio is a web-based survey and feedback platform used by organizations to collect and analyze customer and employee responses. A blind server-side request forgery vulnerability in the survey import feature allows an attacker to force the server to perform HTTP requests to arbitrary destinations, potentially enabling reconnaissance of internal network resources, theft of sensitive data from internal systems, or attacks against third-party services.

Technical details

This is a blind server-side request forgery (SSRF) vulnerability in the survey-import feature of ObjectPlanet Opinio 7.26 rev12562. The vulnerability allows an attacker to craft malicious import requests that cause the server to perform HTTP GET requests to arbitrary destinations without proper validation or sanitization. The attack does not require authentication or user interaction beyond uploading a crafted survey import file. An attacker can exploit this to access internal network resources, retrieve sensitive data from internal systems, or launch attacks against third-party services from the server's perspective. The vulnerability has been patched in Opinio 7.27 (released July 31, 2025) and subsequent versions.

Affected products

  • ObjectPlanet Opinio 7.26 rev12562 and earlier

Timeline

  • 2025-12-02: disclosed
  • 2025-07-31: patched: Fixed in Opinio 7.27

References

Related threats