CVE-2025-13872

EUVD-2025-200216
Blind Server-Side Request Forgery (SSRF) in the survey-import feature of 

 ObjectPlanet Opinio 7.26 rev12562 on 

Web-based platforms allows an attacker to force the server to perform HTTP GET requests via crafted import requests 

 to an arbitrary destination.
SSRF
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTPrimary
9.1 CRITICAL
NETWORK
LOW
NONE
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N