Stored XSS Vulnerability in ENOVIA Change Manager by Dassault Systèmes
CVE-2025-0830

Currently unrated

Key Information:

Vendor
CVE Published:
17 March 2025

What is CVE-2025-0830?

A stored Cross-site Scripting vulnerability in the Meeting Management module of ENOVIA Change Manager allows attackers to embed malicious script code. When users interact with affected versions of the software, the script can execute in their browser sessions without their consent. This poses a significant risk, as it can lead to unauthorized data access, user session hijacking, and other potential security breaches. Users of ENOVIA Change Manager across specified 3DEXPERIENCE releases should review their security measures and apply necessary updates to mitigate this risk.

References

Timeline

  • Vulnerability published

.
CVE-2025-0830 : Stored XSS Vulnerability in ENOVIA Change Manager by Dassault Systèmes