Stored Cross-site Scripting Vulnerability in 3DEXPERIENCE by Dassault Systèmes
CVE-2025-4990
8.7HIGH
What is CVE-2025-4990?
A stored Cross-site Scripting (XSS) vulnerability in the Change Governance functionality of 3DEXPERIENCE products allows attackers to inject malicious script code. This code can be executed in the context of a user's browser session, potentially leading to unauthorized actions or data theft. This vulnerability affects multiple releases, emphasizing the need for immediate attention from users and administrators to safeguard their systems against potential exploits.
Affected Version(s)
Product Manager Release 3DEXPERIENCE R2022x Golden
Product Manager Release 3DEXPERIENCE R2023x Golden
Product Manager Release 3DEXPERIENCE R2024x Golden