PT-2023-16862 · Dsm · Enovia Live Collaboration

Shadi Habbal

·

Published

2023-03-09

·

Updated

2023-03-15

·

CVE-2023-1287

CVSS v3.1

9.8

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions ENOVIA Live Collaboration version V6R2013xE
Description An XSL template vulnerability in the software allows Remote Code Execution.
Recommendations For ENOVIA Live Collaboration version V6R2013xE, update to a version that fixes the XSL template vulnerability to prevent Remote Code Execution.

Fix

Special Elements Injection

Code Injection

Weakness Enumeration

Related Identifiers

CVE-2023-1287

Affected Products

Enovia Live Collaboration