CVE-2023-5599: Stored Cross-site Scripting (XSS) vulnerability affecting 3DDashboard in 3DSwymer from Release 3DEXPERIENCE R2022x through Release 3DEXPERIENCE R2023x
Published Nov 21, 2023
·Updated
A stored Cross-site Scripting (XSS) vulnerability affecting 3DDashboard in 3DSwymer from Release 3DEXPERIENCE R2022x through Release 3DEXPERIENCE R2023x allows an attacker to execute arbitrary script code.
Affected Software
2 affected components
3DExperience by Dassault Systèmes=fp.cfa.2337
3DEXPERIENCE by Dassault Systèmes=fp.cfa.2333
Event History
Nov 21, 2023
CVE Published
via MITRE·09:28 AM
Data Sourced
via MITRE·09:28 AM
DescriptionSeverityWeakness
May 24, 57290
Event
via FIRST·01:24 AM
Frequently Asked Questions
1
What is the vulnerability ID for this security issue?
The vulnerability ID for this security issue is CVE-2023-5599.
2
What is the severity level of CVE-2023-5599?
The severity level of CVE-2023-5599 is medium with a rating of 5.4.
3
Which software versions are affected by CVE-2023-5599?
CVE-2023-5599 affects 3DSwymer in 3DEXPERIENCE R2022x through R2023x.
4
What is the Common Weakness Enumeration (CWE) ID for CVE-2023-5599?
The Common Weakness Enumeration (CWE) ID for CVE-2023-5599 is CWE-79.
5
How can an attacker exploit CVE-2023-5599?
An attacker can exploit CVE-2023-5599 by executing arbitrary script code through a stored Cross-site Scripting (XSS) vulnerability in 3DDashboard.