CVE-2025-10551 identifies a Stored Cross-site Scripting (XSS) vulnerability within the Document Management component of ENOVIA Collaborative Industry Innovator, impacting versions from 3DEXPERIENCE R2023x through R2025x. Rated 8.7 HIGH on the CVSS scale, this flaw allows a remote attacker with low privileges to execute arbitrary script code in a user's browser session, requiring user interaction and leading to high confidentiality and integrity impacts. The attack complexity is low, and the attack vector is network-based. Currently, there is no indication of active exploitation, nor are public exploit modules available in common repositories like Metasploit or ExploitDB. While not on CISA's KEV or Hot List, the vulnerability has generated some community discussion on platforms such as Bluesky and Mastodon.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
>= r2023x, <= r2025xCPE matchmatch criteria | cpe:2.3:o:3ds:3dexperience:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:H/I:H/A:N
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.0 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.0 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.