A security vulnerability has been detected in deco-cx apps up to 0.120.1. Affected by this vulnerability is the function AnalyticsScript of the file website/loaders/analyticsScript.ts of the component Parameter Handler. Such manipulation of the argument url leads to server-side request forgery. The attack can be executed remotely. The exploit has been disclosed publicly and may be used. Upgrading to version 0.120.2 addresses this issue. It is suggested to upgrade the affected component.
Metrics
Affected Vendors & Products
References
History
Mon, 01 Dec 2025 15:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Deco-cx
Deco-cx apps |
|
| Vendors & Products |
Deco-cx
Deco-cx apps |
Sun, 30 Nov 2025 23:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | A security vulnerability has been detected in deco-cx apps up to 0.120.1. Affected by this vulnerability is the function AnalyticsScript of the file website/loaders/analyticsScript.ts of the component Parameter Handler. Such manipulation of the argument url leads to server-side request forgery. The attack can be executed remotely. The exploit has been disclosed publicly and may be used. Upgrading to version 0.120.2 addresses this issue. It is suggested to upgrade the affected component. | |
| Title | deco-cx apps Parameter analyticsScript.ts AnalyticsScript server-side request forgery | |
| Weaknesses | CWE-918 | |
| References |
| |
| Metrics |
cvssV2_0
|
Status: PUBLISHED
Assigner: VulDB
Published: 2025-11-30T23:32:06.222Z
Updated: 2025-11-30T23:32:06.222Z
Reserved: 2025-11-30T13:54:14.862Z
Link: CVE-2025-13796
No data.
Status : Awaiting Analysis
Published: 2025-12-01T00:15:46.670
Modified: 2025-12-01T15:39:33.110
Link: CVE-2025-13796
No data.