PT-2025-48399 · Unknown · Deco-Cx Apps

Cucumbersalad

·

Published

2025-11-30

·

Updated

2025-12-01

·

CVE-2025-13796

CVSS v2.0

6.5

Medium

VectorAV:N/AC:L/Au:S/C:P/I:P/A:P
Name of the Vulnerable Software and Affected Versions deco-cx apps versions up to 0.120.1
Description A security issue exists in deco-cx apps. Manipulation of the url argument within the AnalyticsScript function, located in the website/loaders/analyticsScript.ts file of the Parameter Handler component, can lead to server-side request forgery. This attack can be carried out remotely. The exploit for this issue has been publicly disclosed.
Recommendations Upgrade to version 0.120.2 to address this issue.

Fix

SSRF

Weakness Enumeration

Related Identifiers

CVE-2025-13796

Affected Products

Deco-Cx Apps