CVE-2023-4472: Objectplanet Opinio
Critical severity, CVSS 9.8. EPSS: 0.7% chance of exploitation in the next 30 days.
Objectplanet Opinio version 7.22 and prior uses a cryptographically weak pseudo-random number generator (PRNG) coupled to a predictable seed, which could lead to an unauthenticated account takeover of any user on the application.
Affected products
- Objectplanet Opinio: before 7.23 (fixed in 7.23)
Published 2024-02-01. Last modified 2026-06-17.