CVE 8.7 HIGH

Stored Cross-site Scripting (XSS) vulnerability affecting Requirements in ENOVIA Product Manager from Release 3DEXPERIENCE R2023x through Release 3DEXPERIENCE R2025x_CVE-2025-10554

8.7 / 10
HIGH
CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:H/I:H/A:N

Description

A stored Cross-site Scripting (XSS) vulnerability affecting Requirements in ENOVIA Product Manager from Release 3DEXPERIENCE R2023x through Release 3DEXPERIENCE R2025x allows an attacker to execute arbitrary script code in user's browser session.

AI Analysis

Stored Cross-site Scripting (XSS) vulnerability in ENOVIA Product Manager

Basic Information

ID CVE-2025-10554
Source 3DS
Published Nov 24, 2025 at 15:31
Modified Nov 24, 2025 at 17:59

Affected Product

Vendor Dassault Systèmes
Product ENOVIA Product Manager
Version Release 3DEXPERIENCE R2023x Golden
Affected Versions Dassault Systèmes ENOVIA Product Manager Release 3DEXPERIENCE R2023x Golden
Dassault Systèmes ENOVIA Product Manager Release 3DEXPERIENCE R2024x Golden
Dassault Systèmes ENOVIA Product Manager Release 3DEXPERIENCE R2025x Golden

CWE Classification

AI Assessment

AI Score 8.7 / 10
AI Severity High
Vendor Dassault Systèmes
Product ENOVIA Product Manager
Version Release 3DEXPERIENCE R2023x, Release 3DEXPERIENCE R2024x, Release 3DEXPERIENCE R2025x

References

💭 Join the Security Discussion

🔒 Your email address will not be published. Required fields are marked *

⚠️ Please be respectful and constructive in your comments. Security discussions should remain professional.