CVE-2025-4992: Stored Cross-site Scripting (XSS) vulnerability affecting Service Items Management in Service Process Engineer from Release 3DEXPERIENCE R2024x through Release 3DEXPERIENCE R2025x
A stored Cross-site Scripting (XSS) vulnerability affecting Service Items Management in Service Process Engineer from Release 3DEXPERIENCE R2024x through Release 3DEXPERIENCE R2025x allows an attacker to execute arbitrary script code in user's browser session.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-4992?
CVE-2025-4992 is classified as a stored Cross-site Scripting (XSS) vulnerability, which can be considered high severity due to its potential impact on user sessions.
How do I fix CVE-2025-4992?
To remediate CVE-2025-4992, ensure that you update your 3DEXPERIENCE software to the latest version that is patched against this vulnerability.
Which versions of 3DEXPERIENCE are affected by CVE-2025-4992?
CVE-2025-4992 affects 3DEXPERIENCE software from Release 3DEXPERIENCE R2024x through Release 3DEXPERIENCE R2025x.
What kind of attack is possible with CVE-2025-4992?
CVE-2025-4992 allows an attacker to execute arbitrary script code in a user's browser session, potentially leading to data theft or session hijacking.
Who is the vendor for CVE-2025-4992?
The vendor associated with CVE-2025-4992 is Dassault Systèmes, responsible for the 3DEXPERIENCE platform.