Stored Cross-site Scripting Vulnerability in 3DEXPERIENCE by Dassault Systèmes
CVE-2025-4990

8.7HIGH

Key Information:

Vendor
CVE Published:
30 May 2025

What is CVE-2025-4990?

A stored Cross-site Scripting (XSS) vulnerability in the Change Governance functionality of 3DEXPERIENCE products allows attackers to inject malicious script code. This code can be executed in the context of a user's browser session, potentially leading to unauthorized actions or data theft. This vulnerability affects multiple releases, emphasizing the need for immediate attention from users and administrators to safeguard their systems against potential exploits.

Affected Version(s)

Product Manager Release 3DEXPERIENCE R2022x Golden

Product Manager Release 3DEXPERIENCE R2023x Golden

Product Manager Release 3DEXPERIENCE R2024x Golden

References

CVSS V3.1

Score:
8.7
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
Required
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.
CVE-2025-4990 : Stored Cross-site Scripting Vulnerability in 3DEXPERIENCE by Dassault Systèmes