CVE-2025-0829: Stored Cross-site Scripting (XSS) vulnerability affecting 3D Markup in ENOVIA Collaborative Industry Innovator from Release 3DEXPERIENCE R2022x through Release 3DEXPERIENCE R2024x
A stored Cross-site Scripting (XSS) vulnerability affecting 3D Markup in ENOVIA Collaborative Industry Innovator from Release 3DEXPERIENCE R2022x through Release 3DEXPERIENCE R2024x allows an attacker to execute arbitrary script code in user's browser session.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-0829?
CVE-2025-0829 has a high severity rating due to its potential for executing arbitrary scripts in user sessions.
How do I fix CVE-2025-0829?
To fix CVE-2025-0829, you should update to the latest version of ENOVIA Collaborative Industry Innovator that addresses this vulnerability.
Who is affected by CVE-2025-0829?
CVE-2025-0829 affects users of ENOVIA Collaborative Industry Innovator from Release 3DEXPERIENCE R2022x through Release 3DEXPERIENCE R2024x.
What type of attack does CVE-2025-0829 enable?
CVE-2025-0829 enables stored Cross-site Scripting (XSS) attacks, allowing attackers to run malicious scripts.
Is user data at risk due to CVE-2025-0829?
Yes, CVE-2025-0829 poses a risk to user data as it allows attackers to manipulate user sessions and potentially access sensitive information.