Stored Cross-site Scripting (XSS) Vulnerability Affects 3DSwymer
CVE-2024-7737

8.7HIGH

Key Information:

Status
Vendor
CVE Published:
19 September 2024

What is CVE-2024-7737?

A stored Cross-site Scripting (XSS) vulnerability exists in the 3DSwym application from Dassault Systèmes, spanning from Release 3DEXPERIENCE R2022x to R2024x. This vulnerability allows attackers to inject and execute arbitrary script code within the user's browser session. By exploiting this flaw, an attacker can potentially manipulate user interactions and steal sensitive information, posing significant risks to personal and organizational data security.

Affected Version(s)

3DSwymer Release 3DEXPERIENCE R2022x Golden

3DSwymer Release 3DEXPERIENCE R2023x Golden

3DSwymer Release 3DEXPERIENCE R2024x Golden

References

CVSS V3.1

Score:
8.7
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
Required
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.
CVE-2024-7737 : Stored Cross-site Scripting (XSS) Vulnerability Affects 3DSwymer