CVE 8.7 HIGH

Stored Cross-site Scripting (XSS) vulnerability affecting Specification Management in ENOVIA Specification Manager from Release 3DEXPERIENCE R2023x through Release 3DEXPERIENCE R2025x_CVE-2025-10556

8.7 / 10
HIGH
CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:H/I:H/A:N

Description

A stored Cross-site Scripting (XSS) vulnerability affecting Specification Management in ENOVIA Specification Manager from Release 3DEXPERIENCE R2023x through Release 3DEXPERIENCE R2025x allows an attacker to execute arbitrary script code in user's browser session.

Basic Information

ID CVE-2025-10556
Source 3DS
Published Oct 13, 2025 at 07:36

Affected Product

Vendor Dassault Systèmes
Product ENOVIA Specification Manager
Version Release 3DEXPERIENCE R2023x Golden
Affected Versions Dassault Systèmes ENOVIA Specification Manager Release 3DEXPERIENCE R2023x Golden
Dassault Systèmes ENOVIA Specification Manager Release 3DEXPERIENCE R2024x Golden
Dassault Systèmes ENOVIA Specification Manager Release 3DEXPERIENCE R2025x Golden

CWE Classification

References

💭 Join the Security Discussion

🔒 Your email address will not be published. Required fields are marked *

⚠️ Please be respectful and constructive in your comments. Security discussions should remain professional.