A stored Cross-site Scripting (XSS) vulnerability affecting ENOVIA Collaborative Industry Innovator from Release 3DEXPERIENCE R2022x through Release 3DEXPERIENCE R2024x allows an attacker to execute arbitrary script code in user's browser session.
2024-09-02T12:15:20.723
2024-09-04T14:56:46.947
Analyzed
CVSSv3.1: 8.7 (HIGH)
Type | Vendor | Product | Version/Range | Vulnerable? |
---|---|---|---|---|
Application | 3ds | 3dexperience_enovia | r2022x | Yes |
Application | 3ds | 3dexperience_enovia | r2023x | Yes |
Application | 3ds | 3dexperience_enovia | r2024x | Yes |