Stored Cross-Site Scripting (XSS) Vulnerability in 3DSwymer Release
CVE-2024-7939

5.4MEDIUM

Key Information:

Status
Vendor
CVE Published:
2 September 2024

What is CVE-2024-7939?

A stored Cross-site Scripting (XSS) vulnerability exists within the 3DSwym component of the 3DEXPERIENCE platform. This issue permits an attacker to inject and execute arbitrary script code within the browser session of a user. By exploiting this vulnerability, an attacker may gain unauthorized access to user information or manipulate the user’s session with malicious intent. Security measures are essential to prevent exploitation and mitigate the associated risks.

Affected Version(s)

3DSwymer Release 3DEXPERIENCE R2024x Golden

References

CVSS V3.1

Score:
5.4
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
Required
Scope:
Changed

Timeline

  • Vulnerability published

.