Vulnerabilities > Objectplanet > Medium

DATE CVE VULNERABILITY TITLE RISK
2021-07-31 CVE-2020-26564 XXE vulnerability in Objectplanet Opinio
ObjectPlanet Opinio before 7.15 allows XXE attacks via three steps: modify a .css file to have <!ENTITY content, create a .xml file for a generic survey template (containing a link to this .css file), and import this .xml file at the survey/admin/folderSurvey.do?action=viewImportSurvey['importFile'] URI.
network
low complexity
objectplanet CWE-611
6.5
2021-07-30 CVE-2020-26563 Cross-site Scripting vulnerability in Objectplanet Opinio
ObjectPlanet Opinio before 7.14 allows reflected XSS via the survey/admin/surveyAdmin.do?action=viewSurveyAdmin query string.
network
low complexity
objectplanet CWE-79
6.1
2017-07-03 CVE-2017-10798 Cross-site Scripting vulnerability in Objectplanet Opinio
In ObjectPlanet Opinio before 7.6.4, there is XSS.
network
low complexity
objectplanet CWE-79
6.1