XSS Vulnerability in DECE Software Geodi
CVE-2025-6060

5.4MEDIUM

Key Information:

Status
Vendor
CVE Published:
29 July 2025

What is CVE-2025-6060?

An improper neutralization of input during the web page generation in DECE Software's Geodi allows attackers to execute arbitrary scripts in a user's browser. This vulnerability can lead to unauthorized access to sensitive information, session hijacking, or malicious activity performed on behalf of the victim. Affected versions include all prior to GEODI Setup 9.0.146. Users are encouraged to update their software to mitigate potential risks.

Affected Version(s)

Geodi 0

References

CVSS V3.1

Score:
5.4
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
Required
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Serhat Yapici
Republic of TĂĽrkiye Ministry of Trade
.
CVE-2025-6060 : XSS Vulnerability in DECE Software Geodi