CVE-2024-7736: Reflected Cross-site Scripting (XSS) vulnerability affecting ENOVIA Collaborative Industry Innovator from Release 3DEXPERIENCE R2022x through Release 3DEXPERIENCE R2024x
A reflected Cross-site Scripting (XSS) vulnerability affecting ENOVIA Collaborative Industry Innovator from Release 3DEXPERIENCE R2022x through Release 3DEXPERIENCE R2024x allows an attacker to execute arbitrary script code in user's browser session.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2024-7736?
CVE-2024-7736 has a medium severity rating due to the potential for reflected XSS attacks.
How do I fix CVE-2024-7736?
To fix CVE-2024-7736, you should update to the latest version of ENOVIA Collaborative Industry Innovator that addresses this vulnerability.
Who is affected by CVE-2024-7736?
CVE-2024-7736 affects users of ENOVIA Collaborative Industry Innovator from Release 3DEXPERIENCE R2022x through Release 3DEXPERIENCE R2024x.
What type of attack does CVE-2024-7736 enable?
CVE-2024-7736 enables reflected Cross-site Scripting (XSS) attacks, allowing attackers to execute arbitrary scripts in user sessions.
When was CVE-2024-7736 disclosed?
CVE-2024-7736 was disclosed in 2024, highlighting security vulnerabilities in specific ENOVIA software versions.