CVE-2024-6378: Reflected Cross-site Scripting (XSS) vulnerability affecting ENOVIA Collaborative Industry Innovator from Release 3DEXPERIENCE R2022x through Release 3DEXPERIENCE R2024x
A reflected Cross-site Scripting (XSS) vulnerability affecting ENOVIA Collaborative Industry Innovator from Release 3DEXPERIENCE R2022x through Release 3DEXPERIENCE R2024x allows an attacker to execute arbitrary script code in user's browser session.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2024-6378?
CVE-2024-6378 is considered a high severity vulnerability due to the potential for attackers to execute arbitrary script code in users' browser sessions.
How do I fix CVE-2024-6378?
To fix CVE-2024-6378, upgrade your ENOVIA Collaborative Industry Innovator software to a version beyond Release 3DEXPERIENCE R2024x.
Who is affected by CVE-2024-6378?
CVE-2024-6378 affects users of ENOVIA Collaborative Industry Innovator from Release 3DEXPERIENCE R2022x to Release 3DEXPERIENCE R2024x.
What type of vulnerability is CVE-2024-6378?
CVE-2024-6378 is a reflected Cross-site Scripting (XSS) vulnerability.
What impact does CVE-2024-6378 have on users?
CVE-2024-6378 can allow an attacker to execute arbitrary scripts in the context of the user's browser, potentially leading to data theft or session hijacking.