Vulnerability Monitor

The vendors, products, and vulnerabilities you care about

CVE-2024-8004


A stored Cross-site Scripting (XSS) vulnerability affecting ENOVIA Collaborative Industry Innovator from Release 3DEXPERIENCE R2022x through Release 3DEXPERIENCE R2024x allows an attacker to execute arbitrary script code in user's browser session.


Published

2024-09-02T12:15:20.723

Last Modified

2024-09-04T14:56:46.947

Status

Analyzed

Source

[email protected]

Severity

CVSSv3.1: 8.7 (HIGH)

Weaknesses
  • Type: Secondary
    CWE-79
  • Type: Primary
    CWE-79

Affected Vendors & Products
Type Vendor Product Version/Range Vulnerable?
Application 3ds 3dexperience_enovia r2022x Yes
Application 3ds 3dexperience_enovia r2023x Yes
Application 3ds 3dexperience_enovia r2024x Yes

References