CVE-2025-0830: Stored Cross-site Scripting (XSS) vulnerability affecting Meeting Management in ENOVIA Change Manager from Release 3DEXPERIENCE R2022x through Release 3DEXPERIENCE R2024x
A stored Cross-site Scripting (XSS) vulnerability affecting Meeting Management in ENOVIA Change Manager from Release 3DEXPERIENCE R2022x through Release 3DEXPERIENCE R2024x allows an attacker to execute arbitrary script code in user's browser session.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-0830?
CVE-2025-0830 is classified as a medium severity stored Cross-site Scripting (XSS) vulnerability.
How do I fix CVE-2025-0830?
To fix CVE-2025-0830, ensure that you update to the latest version of ENOVIA Change Manager that addresses this vulnerability.
What versions are affected by CVE-2025-0830?
CVE-2025-0830 affects ENOVIA Change Manager from Release 3DEXPERIENCE R2022x through Release 3DEXPERIENCE R2024x.
What type of attack does CVE-2025-0830 enable?
CVE-2025-0830 enables an attacker to execute arbitrary script code in a user's browser session.
Where can I find more information about CVE-2025-0830?
Additional details and advisories regarding CVE-2025-0830 can be found on the 3DS website.