Stored XSS Vulnerability Affects 3DSwymer in 3DEXPERIENCE R2023x - R2024x Releases
CVE-2024-7938

5.4MEDIUM

Key Information:

Status
Vendor
CVE Published:
2 September 2024

What is CVE-2024-7938?

A stored Cross-site Scripting (XSS) vulnerability present in the 3DDashboard component of 3DSwymer can allow an attacker to inject and execute arbitrary script code within a user's web browser session. This may lead to unauthorized access and data manipulation, compromising user privacy and application integrity. This vulnerability affects multiple releases, rendering earlier versions of the product particularly susceptible to malicious exploits, highlighting the need for timely updates and security patches.

Affected Version(s)

3DSwymer Release 3DEXPERIENCE R2023x Golden

3DSwymer Release 3DEXPERIENCE R2024x Golden

References

CVSS V3.1

Score:
5.4
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
Required
Scope:
Changed

Timeline

  • Vulnerability published

.