Stored XSS Vulnerability in ENOVIA Change Manager by Dassault Systèmes
CVE-2025-0830
Currently unrated
What is CVE-2025-0830?
A stored Cross-site Scripting vulnerability in the Meeting Management module of ENOVIA Change Manager allows attackers to embed malicious script code. When users interact with affected versions of the software, the script can execute in their browser sessions without their consent. This poses a significant risk, as it can lead to unauthorized data access, user session hijacking, and other potential security breaches. Users of ENOVIA Change Manager across specified 3DEXPERIENCE releases should review their security measures and apply necessary updates to mitigate this risk.