CVE-2025-4990: Stored Cross-site Scripting (XSS) vulnerability affecting Change Governance in Product Manager from Release 3DEXPERIENCE R2022x through Release 3DEXPERIENCE R2025x
A stored Cross-site Scripting (XSS) vulnerability affecting Change Governance in Product Manager from Release 3DEXPERIENCE R2022x through Release 3DEXPERIENCE R2025x allows an attacker to execute arbitrary script code in user's browser session.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-4990?
CVE-2025-4990 is classified as a high severity stored Cross-Site Scripting (XSS) vulnerability.
How do I fix CVE-2025-4990?
To fix CVE-2025-4990, update to a patched version of the 3DEXPERIENCE software that addresses this vulnerability.
What versions of 3DEXPERIENCE are affected by CVE-2025-4990?
CVE-2025-4990 affects 3DEXPERIENCE versions from R2022x through R2025x.
What impact does CVE-2025-4990 have on users?
CVE-2025-4990 allows attackers to execute arbitrary script code in a user's browser session, potentially compromising user data and session integrity.
Is there a workaround for CVE-2025-4990?
Currently, there are no documented workarounds for CVE-2025-4990; applying the security patch is the recommended solution.