Vulnerability Monitor

The vendors, products, and vulnerabilities you care about

CVE-2024-6378


A reflected Cross-site Scripting (XSS) vulnerability affecting ENOVIA Collaborative Industry Innovator from Release 3DEXPERIENCE R2022x through Release 3DEXPERIENCE R2024x allows an attacker to execute arbitrary script code in user's browser session.


Published

2024-08-20T14:15:10.127

Last Modified

2024-08-21T15:53:57.750

Status

Analyzed

Source

[email protected]

Severity

CVSSv3.1: 8.7 (HIGH)

Weaknesses
  • Type: Secondary
    CWE-79
  • Type: Primary
    CWE-79

Affected Vendors & Products
Type Vendor Product Version/Range Vulnerable?
Operating System 3ds 3dexperience ≤ r2024x Yes

References