CVE-2025-0832: Stored Cross-site Scripting (XSS) vulnerability affecting Project Gantt in ENOVIA Collaborative Industry Innovator from Release 3DEXPERIENCE R2022x through Release 3DEXPERIENCE R2024x
A stored Cross-site Scripting (XSS) vulnerability affecting Project Gantt in ENOVIA Collaborative Industry Innovator from Release 3DEXPERIENCE R2022x through Release 3DEXPERIENCE R2024x allows an attacker to execute arbitrary script code in user's browser session.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-0832?
CVE-2025-0832 is classified as a moderate severity stored Cross-site Scripting (XSS) vulnerability.
How do I fix CVE-2025-0832?
To fix CVE-2025-0832, update to a secure version of ENOVIA Collaborative Industry Innovator beyond Release 3DEXPERIENCE R2024x.
What software is affected by CVE-2025-0832?
CVE-2025-0832 affects ENOVIA Collaborative Industry Innovator from Release 3DEXPERIENCE R2022x to R2024x.
What type of vulnerability is CVE-2025-0832?
CVE-2025-0832 is a stored Cross-site Scripting (XSS) vulnerability.
Can CVE-2025-0832 allow an attacker to execute code?
Yes, CVE-2025-0832 allows an attacker to execute arbitrary script code in a user's browser session.