ObjectPlanet Opinio Cross-Site Request Forgery Vulnerability

Vulnerability

A Cross-Site Request Forgery (CSRF) vulnerability has been identified in the resource management feature of ObjectPlanet Opinio version 7.26 prior to 7.27. This vulnerability allows an attacker to upload files on behalf of connected users and access those files without authentication.

Impact

Exploitation of this vulnerability could lead to unauthorized file uploads and access to those files, potentially allowing for further exploitation or information disclosure.

Remediation

Users are advised to update to ObjectPlanet Opinio version 7.27 or later, where this vulnerability has been addressed.

Added: Dec 2, 2025, 10:20 AM
Updated: Dec 2, 2025, 6:03 PM

Vulnerability Rating

Custom Algorithm
spread
1.9
impact
0.6
exploitability
5.2
remediation
7.7
relevance
1.3
threat
0.0
urgency
2.9
incentive
1.7

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.