CVE-2025-10551
8.7Dassault Systèmes · ENOVIA Collaborative Industry Innovator
A stored cross-site scripting (XSS) vulnerability in ENOVIA Collaborative Industry Innovator allows authenticated attackers to execute arbitrary script code within a victim's browser session.
Executive summary
A stored cross-site scripting vulnerability in Dassault Systèmes ENOVIA Collaborative Industry Innovator, rated at 8.7 High, poses a significant risk of unauthorized session manipulation and data theft.
Vulnerability
The flaw is a stored cross-site scripting (CWE-79) vulnerability within the Document Management component. An authenticated user with low privileges can inject malicious scripts that execute in the context of another user's browser session.
Business impact
The CVSS score of 8.7 reflects the high potential for impact on confidentiality and integrity. Successful exploitation allows an attacker to hijack user sessions, steal sensitive session tokens, or perform unauthorized actions on behalf of authenticated users, potentially leading to a full compromise of document management workflows and sensitive intellectual property.
Remediation
Immediate Action: Review the official security advisory from Dassault Systèmes to identify and apply the specific patches or configuration changes required for your version of the 3DEXPERIENCE platform.
Proactive Monitoring: Monitor web application logs for suspicious script injections or unusual patterns in document metadata fields that could indicate an attempt to store malicious payloads.
Compensating Controls: Deploy or tune a Web Application Firewall (WAF) to detect and block common XSS patterns in HTTP requests directed at the Document Management module.
Exploitation status
Public Exploit Available: Unknown
Analyst recommendation
Given the high CVSS severity and the nature of XSS in collaborative industry environments, organizations should prioritize patching as soon as the vendor provides the necessary updates. Until patches are applied, administrators should enforce strict access controls and minimize the number of users with privileges to modify document metadata.