CVE-2025-10551 PUBLISHED

Stored Cross-site Scripting (XSS) vulnerability affecting Document Management in ENOVIA Collaborative Industry Innovator from Release 3DEXPERIENCE R2023x through Release 3DEXPERIENCE R2025x

Assigner: 3DS
Reserved: 16.09.2025 Published: 31.03.2026 Updated: 31.03.2026

A Stored Cross-site Scripting (XSS) vulnerability affecting Document Management in ENOVIA Collaborative Industry Innovator from Release 3DEXPERIENCE R2023x through Release 3DEXPERIENCE R2025x allows an attacker to execute arbitrary script code in user's browser session.

Metrics

CVSS Vector: CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:H/I:H/A:N
CVSS Score: 8.7

Product Status

Vendor Dassault Systèmes
Product ENOVIA Collaborative Industry Innovator
Versions Default: unaffected
  • affected from Release 3DEXPERIENCE R2023x Golden to Release 3DEXPERIENCE R2023x.FP.CFA.2541 (incl.)
  • affected from Release 3DEXPERIENCE R2024x Golden to Release 3DEXPERIENCE R2024x.FP.CFA.2537 (incl.)
  • affected from Release 3DEXPERIENCE R2025x Golden to Release 3DEXPERIENCE R2025x.FP.CFA.2514 (incl.)

References

Problem Types

  • CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') CWE