PT-2025-11499 · Ds Systemes · Enovia Collaborative Industry Innovator

Published

2025-03-17

·

Updated

2025-10-22

·

CVE-2025-0833

CVSS v3.1

8.7

High

VectorAV:N/AC:L/PR:L/UI:R/S:C/C:H/I:H/A:N
Name of the Vulnerable Software and Affected Versions ENOVIA Collaborative Industry Innovator versions 3DEXPERIENCE R2023x through 3DEXPERIENCE R2024x
Description A stored Cross-site Scripting (XSS) vulnerability affects Route Management in ENOVIA Collaborative Industry Innovator, allowing an attacker to execute arbitrary script code in a user's browser session.
Recommendations Update from Release 3DEXPERIENCE R2023x to Release 3DEXPERIENCE R2024x to resolve the issue. As a temporary workaround, consider restricting access to the Route Management feature in ENOVIA Collaborative Industry Innovator until the update is applied.

Fix

XSS

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2025-11560
CVE-2025-0833

Affected Products

Enovia Collaborative Industry Innovator