- Description
- A stored Cross-site Scripting (XSS) vulnerability affecting 3D Navigate in ENOVIA Collaborative Industry Innovator from Release 3DEXPERIENCE R2022x through Release 3DEXPERIENCE R2024x allows an attacker to execute arbitrary script code in user's browser session.
- Source
- 3DS.Information-Security@3ds.com
- NVD status
- Received
CVSS 3.1
- Type
- Secondary
- Base score
- 8.7
- Impact score
- 5.8
- Exploitability score
- 2.3
- Vector string
- CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:H/I:H/A:N
- Severity
- HIGH
- 3DS.Information-Security@3ds.com
- CWE-79
- Hype score
- Not currently trending
New post from https://t.co/uXvPWJyEiR (CVE-2025-0826 | Dassault Systèmes ENOVIA Collaborative Industry Innovator cross site scripting) has been published on https://t.co/kkEsWqWon1
@WolfgangSesin
17 Mar 2025
7 Impressions
0 Retweets
0 Likes
0 Bookmarks
0 Replies
0 Quotes
[CVE-2025-0826: HIGH] Warning: A stored Cross-site Scripting vulnerability in ENOVIA Collaborative Industry Innovator exposes users to browser session hijacking. Update to Release 3DEXPERIENCE R2024x for protection.#cybersecurity,#vulnerability https://t.co/3UcOIz6gKJ https://t.c
@CveFindCom
17 Mar 2025
17 Impressions
0 Retweets
0 Likes
0 Bookmarks
0 Replies
0 Quotes