PT-2025-48399 · Unknown · Deco-Cx Apps

·

CVE-2025-13796

·

Published

2025-11-30

·

Updated

2025-12-01

CVSS v2.0

6.5

Medium

VectorAV:N/AC:L/Au:S/C:P/I:P/A:P
Name of the Vulnerable Software and Affected Versions deco-cx apps versions up to 0.120.1
Description A security issue exists in deco-cx apps. Manipulation of the url argument within the AnalyticsScript function, located in the website/loaders/analyticsScript.ts file of the Parameter Handler component, can lead to server-side request forgery. This attack can be carried out remotely. The exploit for this issue has been publicly disclosed.
Recommendations Upgrade to version 0.120.2 to address this issue.

Exploit

Fix

SSRF

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2025-13796

Affected Products

Deco-Cx Apps