CVE-2025-10557: Stored Cross-site Scripting (XSS) vulnerability affecting Issue Management in ENOVIA Collaborative Industry Innovator from Release 3DEXPERIENCE R2022x through Release 3DEXPERIENCE R2025x
A stored Cross-site Scripting (XSS) vulnerability affecting Issue Management in ENOVIA Collaborative Industry Innovator from Release 3DEXPERIENCE R2022x through Release 3DEXPERIENCE R2025x allows an attacker to execute arbitrary script code in user's browser session.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-10557?
CVE-2025-10557 is classified as a stored Cross-site Scripting (XSS) vulnerability.
How do I fix CVE-2025-10557?
To mitigate CVE-2025-10557, ensure you sanitize and validate user input in the ENOVIA Collaborative Industry Innovator application.
What versions are affected by CVE-2025-10557?
CVE-2025-10557 affects ENOVIA Collaborative Industry Innovator from Release 3DEXPERIENCE R2022x through Release 3DEXPERIENCE R2025x.
What impact does CVE-2025-10557 have on users?
CVE-2025-10557 allows attackers to execute arbitrary script code in a user's browser session, compromising user security.
Is there a workaround for CVE-2025-10557?
There are no specific workarounds for CVE-2025-10557; updating to a secure version is recommended.