CVE-2024-7737: Stored Cross-site Scripting (XSS) vulnerability affecting 3DSwym in 3DSwymer from Release 3DEXPERIENCE R2022x through Release 3DEXPERIENCE R2024x
Published Sep 19, 2024
·Updated
A stored Cross-site Scripting (XSS) vulnerability affecting 3DSwym in 3DSwymer from Release 3DEXPERIENCE R2022x through Release 3DEXPERIENCE R2024x allows an attacker to execute arbitrary script code in user's browser session.
Affected Software
1 affected component
3DS 3DSwym>=R2022x<=R2024x
Event History
Sep 19, 2024
CVE Published
via MITRE·03:19 PM
Data Sourced
via MITRE·03:19 PM
DescriptionSeverityWeakness
Data Sourced
via NVD·04:15 PM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What is the severity of CVE-2024-7737?
CVE-2024-7737 is classified as a high-severity stored Cross-site Scripting (XSS) vulnerability.
2
How do I fix CVE-2024-7737?
To remediate CVE-2024-7737, update 3DSwym to a patched version specified in the vendor's advisory.
3
Who is affected by CVE-2024-7737?
CVE-2024-7737 affects users of 3DSwym from 3DEXPERIENCE R2022x to R2024x.
4
What type of vulnerability is CVE-2024-7737?
CVE-2024-7737 is a stored Cross-site Scripting (XSS) vulnerability.
5
Can CVE-2024-7737 allow an attacker access to sensitive information?
Yes, CVE-2024-7737 can allow attackers to execute arbitrary script code, potentially leading to access to sensitive information in a user's session.