CVE-2025-10554
8.7Dassault Systèmes · ENOVIA Product Manager
A stored Cross-site Scripting (XSS) vulnerability in ENOVIA Product Manager allows an authenticated attacker to execute arbitrary script code within a victim's browser session.
Executive summary
A stored Cross-site Scripting vulnerability in Dassault Systèmes ENOVIA Product Manager exposes users to potential session hijacking and unauthorized actions by allowing the execution of malicious scripts.
Vulnerability
This is a stored Cross-site Scripting (XSS) vulnerability (CWE-79) residing within the Requirements module. The vulnerability requires the attacker to have low-level authenticated access to the system to inject malicious scripts that execute in the context of other users.
Business impact
Successful exploitation of this vulnerability allows an attacker to execute unauthorized scripts, which can lead to session hijacking, sensitive data theft, or unauthorized actions performed on behalf of the victim. With a CVSS score of 8.7, this flaw represents a high risk, particularly in environments where ENOVIA manages critical intellectual property or product data.
Remediation
Immediate Action: Review the official security advisory from Dassault Systèmes and apply the identified patches or security updates to the affected ENOVIA releases as soon as they are made available.
Proactive Monitoring: Monitor web application access logs for unusual patterns, such as unexpected script tags or encoded characters being submitted to the Requirements module.
Compensating Controls: Deploy or update Web Application Firewall (WAF) rules to detect and block common XSS attack patterns and script injection attempts targeting the affected application endpoints.
Exploitation status
Public Exploit Available: No — there is no confirmed public exploit available.
Analyst recommendation
Given the high CVSS severity score, organizations should prioritize patching these specific versions of ENOVIA Product Manager. Administrators must ensure that all users with access to the Requirements module are aware of potential phishing or malicious links while the software remains in an unpatched state.