CVE-2025-10558: Stored Cross-site Scripting (XSS) vulnerability affecting 3DSearch in 3DSwymer on Release 3DEXPERIENCE R2025x
Published Oct 13, 2025
·Updated
A stored Cross-site Scripting (XSS) vulnerability affecting 3DSearch in 3DSwymer on Release 3DEXPERIENCE R2025x allows an attacker to execute arbitrary script code in user's browser session.
Affected Software
2 affected components
Dassault Systèmes 3DSwymer
3DS 3DSwymer=r2025x
Event History
Oct 13, 2025
CVE Published
via MITRE·07:36 AM
Data Sourced
via MITRE·07:36 AM
DescriptionSeverityWeakness
Data Sourced
via NVD·08:15 AM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2025-10558?
CVE-2025-10558 is classified as a stored Cross-site Scripting (XSS) vulnerability.
2
How do I fix CVE-2025-10558?
To mitigate CVE-2025-10558, ensure that proper input validation and output encoding are implemented in the 3DSearch feature.
3
Who is affected by CVE-2025-10558?
CVE-2025-10558 affects users of Dassault Systèmes 3DSwymer on Release 3DEXPERIENCE R2025x.
4
What type of attack can CVE-2025-10558 facilitate?
CVE-2025-10558 allows an attacker to execute arbitrary script code in a user's browser session.
5
Is there a patch available for CVE-2025-10558?
As of now, check the official Dassault Systèmes channels for a security patch specifically addressing CVE-2025-10558.