CVE-2025-0832
CVSS 3.1 Score 8.7 of 10 (high)
Details
Summary
CVE-2025-0832 is a stored Cross-site Scripting (XSS) vulnerability that affects Project Gantt in ENOVIA Collaborative Industry Innovator from releases R2022x through R2024x. This issue permits an attacker to inject and execute arbitrary scripts in a user's browser session, potentially leading to the theft of sensitive information or unauthorized actions. Successful exploitation of this vulnerability requires the attacker to have the ability to manipulate data within the affected application. Users are advised to update their software to the latest version to mitigate this risk.
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.