Home
HIGH: 7.2 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:L/I:L/A:NDefault status
unaffected
Any version before GEODI Setup 9.0.146
affected
Description
Improper Neutralization of CRLF Sequences ('CRLF Injection') vulnerability in DECE Software Geodi allows HTTP Request Splitting. This issue affects Geodi: before GEODI Setup 9.0.146.
Problem types
CWE-93 Improper Neutralization of CRLF Sequences ('CRLF Injection')
Product status
Any version before GEODI Setup 9.0.146
Credits
Serhat Yapici
Republic of Türkiye Ministry of Trade
References
www.usom.gov.tr/bildirim/tr-25-0182
siberguvenlik.gov.tr/guvenlik-bildirimleri/detay/tr-25-0182