CVE-2025-12956

8.7

Dassault Systèmes · ENOVIA Collaborative Industry Innovator

A reflected Cross-site Scripting (XSS) vulnerability in ENOVIA Collaborative Industry Innovator allows authenticated attackers to execute arbitrary script code in a user's browser session.

Executive summary

A reflected Cross-site Scripting vulnerability in Dassault Systèmes ENOVIA Collaborative Industry Innovator poses a significant risk of session hijacking and unauthorized actions by authenticated attackers.

Vulnerability

This is a reflected Cross-site Scripting (CWE-79) vulnerability where the application fails to properly sanitize user-supplied input. An authenticated attacker can leverage this flaw to execute malicious scripts within the context of another user's browser session.

Business impact

The CVSS score of 8.7 indicates a high severity rating, primarily due to the potential for high impact on confidentiality and integrity. Successful exploitation could lead to the theft of sensitive session tokens, unauthorized access to proprietary project data, or the execution of unauthorized actions on behalf of legitimate users.

Remediation

Immediate Action: Review the official Dassault Systèmes trust center security advisory for the latest available security patches or configuration changes. Apply all recommended vendor updates to the affected 3DEXPERIENCE platform releases as soon as they are made available.

Proactive Monitoring: Monitor web application logs for suspicious URL parameters containing encoded script tags or unusual JavaScript patterns. Implement content security policies to restrict the execution of unauthorized scripts within the browser environment.

Compensating Controls: Deploy a Web Application Firewall with robust XSS filtering rules to detect and block malicious payloads directed at the application's endpoints.

Exploitation status

Public Exploit Available: Unknown

Analyst recommendation

Given the high CVSS severity, organizations utilizing the affected releases of ENOVIA Collaborative Industry Innovator must prioritize the identification and remediation of this flaw. Administrators should monitor the vendor security portal closely for the release of specific patches and ensure that security controls are tightened to prevent script injection until updates are successfully applied.

More Dassault Systèmes CVEs

Sources