CVE-2025-13871

Publication date

2025-12-02 09:42:51

Family

TCS-CERT

State

PUBLISHED

Description

Cross-Site Request Forgery (CSRF) in the resource-management feature of ObjectPlanet Opinio 7.26 rev12562 allows to upload files on behalf of the connected users and then access such files without authentication.