CVE-2025-0827: Stored Cross-site Scripting (XSS) vulnerability affecting 3DPlay in 3DSwymer from Release 3DEXPERIENCE R2022x through Release 3DEXPERIENCE R2024x
A stored Cross-site Scripting (XSS) vulnerability affecting 3DPlay in 3DSwymer from Release 3DEXPERIENCE R2022x through Release 3DEXPERIENCE R2024x allows an attacker to execute arbitrary script code in user's browser session.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-0827?
CVE-2025-0827 is classified as a high severity vulnerability due to its potential for allowing arbitrary script code execution in user's browser sessions.
How do I fix CVE-2025-0827?
To mitigate CVE-2025-0827, ensure to update to the latest version of 3DSwymer beyond Release 3DEXPERIENCE R2024x.
What type of vulnerability is CVE-2025-0827?
CVE-2025-0827 is a stored Cross-site Scripting (XSS) vulnerability.
Which versions of 3DSwymer are affected by CVE-2025-0827?
CVE-2025-0827 affects 3DSwymer versions from Release 3DEXPERIENCE R2022x through Release 3DEXPERIENCE R2024x.
What can an attacker do with CVE-2025-0827?
An attacker exploiting CVE-2025-0827 can execute arbitrary script code within a user's browser session.