8.7
/ 10
HIGH
CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:H/I:H/A:N
Description
A stored Cross-site Scripting (XSS) vulnerability affecting 3DSearch in 3DSwymer on Release 3DEXPERIENCE R2025x allows an attacker to execute arbitrary script code in user's browser session.
Basic Information
ID
CVE-2025-10558
Source
3DS
Published
Oct 13, 2025 at 07:36
Affected Product
Vendor
Dassault Systèmes
Product
3DSwymer
Version
Release 3DEXPERIENCE R2025x Golden
Affected Versions
Dassault Systèmes 3DSwymer Release 3DEXPERIENCE R2025x Golden