ENOVIA Live Collaboration V6R2013xE is affected by an XSL template injection vulnerability
CVE-2023-1287

9CRITICAL

Key Information:

Vendor
CVE Published:
9 March 2023

What is CVE-2023-1287?

ENOVIA Live Collaboration, a product of Dassault Systèmes, has an XSL template vulnerability that could allow an attacker to execute arbitrary code remotely. This could lead to unauthorized access and manipulation of sensitive data within the affected system. It is critical to assess and mitigate exposure to this vulnerability promptly to secure your environment.

Affected Version(s)

ENOVIA Live Collaboration V6R2013xE Golden

References

CVSS V3.1

Score:
9
Severity:
CRITICAL
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
High
Privileges Required:
None
User Interaction:
None
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Shadi Habbal from TĂśV Rheinland i-sec GmbH
.