A stored Cross-site Scripting (XSS) vulnerability affecting Product Explorer in ENOVIA Collaborative Industry Innovator on Release 3DEXPERIENCE R2024x allows an attacker to execute arbitrary script code in user's browser session.
References
Link | Resource |
---|---|
https://www.3ds.com/vulnerability/advisories |
Configurations
No configuration.
History
17 Mar 2025, 14:15
Type | Values Removed | Values Added |
---|---|---|
New CVE |
Information
Published : 2025-03-17 14:15
Updated : 2025-03-17 14:15
NVD link : CVE-2025-0600
Mitre link : CVE-2025-0600
CVE.ORG link : CVE-2025-0600
JSON object : View
Products Affected
No product.
CWE
CWE-79
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')