CVE-2025-0600

CVSS 3.1 Score 8.7 of 10 (high)

Details

Published Mar 17, 2025
CWE ID 79

Summary

CVE-2025-0600 is a stored Cross-site Scripting (XSS) vulnerability affecting Product Explorer in ENOVIA Collaborative Industry Innovator on Release 3DEXPERIENCE R2024x. An attacker can exploit this weakness by injecting malicious scripts into a targeted user's browser session via the Product Explorer interface. Successful exploitation could lead to unauthorized access, data theft, or session hijacking. Users are advised to update their software to the latest version or contact their system administrator for further assistance.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share