CVE-2025-10551: Stored Cross-site Scripting (XSS) vulnerability affecting Document Management in ENOVIA Collaborative Industry Innovator from Release 3DEXPERIENCE R2023x through Release 3DEXPERIENCE R2025x
A Stored Cross-site Scripting (XSS) vulnerability affecting Document Management in ENOVIA Collaborative Industry Innovator from Release 3DEXPERIENCE R2023x through Release 3DEXPERIENCE R2025x allows an attacker to execute arbitrary script code in user's browser session.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-10551?
CVE-2025-10551 is classified as a stored Cross-site Scripting (XSS) vulnerability.
How do I fix CVE-2025-10551?
To mitigate CVE-2025-10551, users should update their ENOVIA Collaborative Industry Innovator software to a version beyond 3DEXPERIENCE R2025x.
Which versions of software are affected by CVE-2025-10551?
CVE-2025-10551 affects ENOVIA Collaborative Industry Innovator from release 3DEXPERIENCE R2023x through R2025x.
What is the impact of CVE-2025-10551?
The impact of CVE-2025-10551 includes the potential for attackers to execute malicious scripts in the context of a user's browser.
Who is the vendor for CVE-2025-10551?
The vendor for CVE-2025-10551 is Dassault Systèmes.