Stored Cross-site Scripting Vulnerability in Results Analytics of 3DEXPERIENCE
CVE-2025-4988
What is CVE-2025-4988?
A stored Cross-site Scripting (XSS) vulnerability exists in the Results Analytics feature of the 3DEXPERIENCE platform, affecting versions from Release R2022x to R2024x. This security flaw permits attackers to insert and execute arbitrary script code within a user's browser session, which could lead to unauthorized access to sensitive information and user sessions. Organizations using these versions should apply necessary patches and review their security practices to mitigate potential exploitation.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.
Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.
Affected Version(s)
Multidisciplinary Optimization Engineer Release 3DEXPERIENCE R2022x Golden
Multidisciplinary Optimization Engineer Release 3DEXPERIENCE R2023x Golden
Multidisciplinary Optimization Engineer Release 3DEXPERIENCE R2024x Golden
References
CVSS V3.1
Timeline
Vulnerability published
Vulnerability Reserved
