CVE-2025-0601
CVSS 3.1 Score 8.7 of 10 (high)
Details
Summary
CVE-2025-0601 is a stored Cross-site Scripting (XSS) vulnerability that affects Issue Management in ENOVIA Collaborative Industry Innovator from versions R2022x through R2024x. This issue allows an attacker to inject malicious code into a web page viewed by other users, potentially taking control of their browser sessions and executing arbitrary scripts. Successful exploitation could lead to information disclosure, session hijacking, or other forms of unauthorized access, posing a significant risk to organizations using the affected software. It is recommended that users update to the latest version of ENOVIA Collaborative Industry Innovator to mitigate this vulnerability.
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.