CVE-2024-6380: Reflected Cross-site Scripting (XSS) vulnerability affecting ENOVIA Collaborative Industry Innovator from Release 3DEXPERIENCE R2022x through Release 3DEXPERIENCE R2024x
A reflected Cross-site Scripting (XSS) vulnerability affecting ENOVIA Collaborative Industry Innovator from Release 3DEXPERIENCE R2022x through Release 3DEXPERIENCE R2024x allows an attacker to execute arbitrary script code in user's browser session.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2024-6380?
CVE-2024-6380 is a high-severity vulnerability allowing reflected Cross-Site Scripting (XSS) attacks.
How do I fix CVE-2024-6380?
To fix CVE-2024-6380, it is recommended to update ENOVIA Collaborative Industry Innovator to a secure version beyond R2024x.
What versions of ENOVIA Collaborative Industry Innovator are affected by CVE-2024-6380?
CVE-2024-6380 affects ENOVIA Collaborative Industry Innovator versions from Release R2022x through Release R2024x.
What are the potential impacts of CVE-2024-6380?
The potential impacts of CVE-2024-6380 include unauthorized script execution in the user's browser, leading to data theft or session hijacking.
Is CVE-2024-6380 a client-side or server-side vulnerability?
CVE-2024-6380 is a client-side vulnerability, specifically a reflected Cross-Site Scripting (XSS) issue.