Arbitrary Script Execution Vulnerability in ENOVIA Collaborative Industry Innovator
CVE-2024-7736

8.7HIGH

What is CVE-2024-7736?

A reflected Cross-site Scripting (XSS) vulnerability in the ENOVIA Collaborative Industry Innovator from 3DS allows attackers to inject and execute arbitrary script code within a user's browser session. This weakness can potentially compromise user data and session integrity, creating significant security risks for organizations relying on this software.

Affected Version(s)

ENOVIA Collaborative Industry Innovator Release 3DEXPERIENCE R2022x Golden

ENOVIA Collaborative Industry Innovator Release 3DEXPERIENCE R2023x Golden

ENOVIA Collaborative Industry Innovator Release 3DEXPERIENCE R2024x Golden

References

CVSS V3.1

Score:
8.7
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
Required
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.