CVE-2025-4991 – “3DEXPERIENCE Collaborative Industry Innovator Stored XSS”

The following table lists the changes that have been made to the
CVE-2025-4991 vulnerability over time.

Vulnerability history details can be useful for understanding the evolution
of a vulnerability, and for identifying the most recent changes that may
impact the vulnerability’s severity, exploitability, or other characteristics.

  • New CVE Received
    by [email protected]

    May. 30, 2025

    Action Type Old Value New Value
    Added Description A stored Cross-site Scripting (XSS) vulnerability affecting 3D Markup in Collaborative Industry Innovator from Release 3DEXPERIENCE R2022x through Release 3DEXPERIENCE R2025x allows an attacker to execute arbitrary script code in user’s browser session.
    Added CVSS V3.1 AV:N/AC:L/PR:L/UI:R/S:C/C:H/I:H/A:N
    Added CWE CWE-79
    Added Reference https://www.3ds.com/vulnerability/advisories
Share the Post:

Related Posts