PT-2024-17434 · Ds Systemes · Enovia Collaborative Industry Innovator

Published

2024-12-16

·

Updated

2025-10-22

·

CVE-2024-12092

CVSS v3.1

8.7

High

VectorAV:N/AC:L/PR:L/UI:R/S:C/C:H/I:H/A:N
Name of the Vulnerable Software and Affected Versions ENOVIA Collaborative Industry Innovator on Release 3DEXPERIENCE R2024x
Description A stored Cross-site Scripting (XSS) issue allows an attacker to execute arbitrary script code in a user's browser session. This enables the attacker to perform actions as the victim user, potentially leading to unauthorized access or data manipulation. No information is provided about the estimated number of potentially affected devices worldwide or real-world incidents where this issue was exploited.
Recommendations For ENOVIA Collaborative Industry Innovator on Release 3DEXPERIENCE R2024x, at the moment, there is no information about a newer version that contains a fix for this vulnerability.

XSS

Weakness Enumeration

Related Identifiers

CVE-2024-12092

Affected Products

Enovia Collaborative Industry Innovator