CVE-2025-12956: Reflected Cross-site Scripting (XSS) vulnerability affecting ENOVIA Collaborative Industry Innovator from Release 3DEXPERIENCE R2022x through Release 3DEXPERIENCE R2025x
A reflected Cross-site Scripting (XSS) vulnerability affecting ENOVIA Collaborative Industry Innovator from Release 3DEXPERIENCE R2022x through Release 3DEXPERIENCE R2025x allows an attacker to execute arbitrary script code in user's browser session.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-12956?
CVE-2025-12956 has a high severity rating due to its potential to allow attackers to execute arbitrary script code in user sessions.
How do I fix CVE-2025-12956?
To fix CVE-2025-12956, upgrade to a patched version of ENOVIA Collaborative Industry Innovator provided by Dassault Systèmes.
What versions are affected by CVE-2025-12956?
CVE-2025-12956 affects all versions of ENOVIA Collaborative Industry Innovator from Release 3DEXPERIENCE R2022x through Release 3DEXPERIENCE R2025x.
What type of vulnerability is CVE-2025-12956?
CVE-2025-12956 is classified as a reflected Cross-site Scripting (XSS) vulnerability.
Who is the vendor for CVE-2025-12956?
The vendor for CVE-2025-12956 is Dassault Systèmes.