Junglewise Threat Intelligence

CVE-2025-6060: DECE Software Geodi Cross-Site Scripting

CVE-2025-6060 · Severity: medium · CVSS 5.4 · Published 2025-07-29

Executive brief

DECE Software Geodi, an enterprise search and data discovery platform, is vulnerable to a security flaw that could allow an attacker to execute malicious scripts in a user's browser. By tricking a logged-in user into interacting with a specific link or page, an attacker could potentially steal session information or perform unauthorized actions on behalf of that user. This could lead to unauthorized access to sensitive corporate data indexed by the platform.

Technical details

A Cross-Site Scripting (XSS) vulnerability exists in DECE Software Geodi due to improper neutralization of user-supplied input during web page generation (CWE-79). The vulnerability is network-reachable and requires low-privileged authentication (PR:L) and user interaction (UI:R). An attacker can exploit this by injecting malicious scripts into the web interface, which are then executed in the context of the victim's browser session. This can lead to session hijacking, unauthorized data access, or modification of the application's behavior for the affected user. The issue is resolved in GEODI Setup version 9.0.146.

Affected products

  • DECE Software Geodi before GEODI Setup 9.0.146

Timeline

  • 2025-07-29: disclosed
  • 2025-07-29: advisory

References

Related threats