CVE-2025-10552: Stored Cross-site Scripting (XSS) vulnerability affecting 3DSwym in 3DSwymer on Release 3DEXPERIENCE R2025x
A stored Cross-site Scripting (XSS) vulnerability affecting 3DSwym in 3DSwymer on Release 3DEXPERIENCE R2025x allows an attacker to execute arbitrary script code in user's browser session.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-10552?
CVE-2025-10552 is classified as a stored Cross-site Scripting (XSS) vulnerability, which can lead to significant security risks.
How do I fix CVE-2025-10552?
To fix CVE-2025-10552, it is recommended to apply the latest security patches provided by Dassault Systèmes for the 3DEXPERIENCE platform.
Which versions of 3DEXPERIENCE are affected by CVE-2025-10552?
CVE-2025-10552 affects the 3DSwym application in the 3DEXPERIENCE R2025x release.
What impact does CVE-2025-10552 have on users?
CVE-2025-10552 allows an attacker to execute arbitrary script code in the user's browser session, potentially compromising user data.
Is there a workaround for CVE-2025-10552?
As of now, no official workaround has been published for CVE-2025-10552; users should prioritize applying the provided security updates.