CVE-2025-0596
CVSS 3.1 Score 8.7 of 10 (high)
Details
Summary
CVE-2025-0596 is a stored Cross-site Scripting (XSS) vulnerability that impacts the Bookmark Editor in ENOVIA Collaborative Industry Innovator, specifically on Release 3DEXPERIENCE R2024x. This issue enables attackers to inject and execute malicious script code in a user's browser session. By exploiting this vulnerability, an attacker can potentially gain unauthorized access to sensitive information or take control of the affected user's account. This can lead to various attacks, including data theft or unauthorized actions within the system. Users are advised to apply the necessary patches to mitigate this risk.
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.