CVE-2024-12090

CVSS 3.1 Score 8.7 of 10 (high)

Details

Published Dec 16, 2024
CWE ID 79

Summary

CVE-2024-12090 is a stored Cross-site Scripting (XSS) vulnerability affecting ENOVIA Collaborative Industry Innovator on Release 3DEXPERIENCE R2024x. An attacker can exploit this issue to inject and execute arbitrary script code in a user's browser session, potentially stealing sensitive information or taking control of the user's account. This vulnerability poses a significant risk to organizations using this software and emphasizes the importance of keeping software up-to-date with the latest security patches. Users are advised to apply the necessary fixes as soon as possible to mitigate the risk of a successful attack.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share