Executive brief
DECE Software Geodi, a smart search and content management platform, is vulnerable to a security flaw that allows attackers to manipulate web traffic. By injecting special characters into web requests, an attacker can potentially redirect users to malicious sites or poison the system's cache. This could lead to unauthorized access to sensitive information or the disruption of normal business operations.
Technical details
A CRLF (Carriage Return Line Feed) injection vulnerability exists in DECE Software Geodi due to improper neutralization of special character sequences in HTTP headers. An unauthenticated remote attacker can exploit this by sending specially crafted network requests that include CRLF sequences, leading to HTTP Request Splitting. This allows the attacker to inject additional headers or split a single request into multiple requests, which can be used for cache poisoning, cross-site scripting (XSS), or bypassing security filters. The vulnerability is addressed in GEODI Setup version 9.0.146.
Affected products
- DECE Software Geodi before GEODI Setup 9.0.146
Timeline
- 2025-07-29: disclosed
- 2025-07-29: advisory