Stored Cross-Site Scripting Vulnerability in ENOVIA Collaborative Industry Innovator
CVE-2024-12089
What is CVE-2024-12089?
CVE-2024-12089 is a critical stored Cross-site Scripting (XSS) vulnerability that affects the ENOVIA Collaborative Industry Innovator, impacting versions from 3DEXPERIENCE R2022x through R2024x. This vulnerability allows attackers to inject and execute arbitrary script code within a user's browser session, which can lead to unauthorized actions and data exposure. Organizations using the affected products should prioritize updating their systems to mitigate potential risks. For more information and guidance on how to address this vulnerability, refer to the official advisories provided by Dassault Systèmes.
Affected Version(s)
ENOVIA Collaborative Industry Innovator Release 3DEXPERIENCE R2022x Golden
ENOVIA Collaborative Industry Innovator Release 3DEXPERIENCE R2023x Golden
ENOVIA Collaborative Industry Innovator Release 3DEXPERIENCE R2024x Golden