Dassault Systèmes 3DEXPERIENCE是法国达索系统(Dassault Systèmes)公司的一种业务与创新平台。 Dassault Systèmes 3DEXPERIENCE R2022x版本至R2024x版本存在安全漏洞,该漏洞源于3DPassport存在URL重定向到不受信任站点漏洞,允许攻击者通过精心设计的UR将用户重定向到任意网站。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| Dassault Systèmes | 3DSwymer | Release 3DEXPERIENCE R2022x Golden ~ Release 3DEXPERIENCE R2022x.FP.CFA.2424 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2024-6378 | 8.7 HIGH | Reflected Cross-site Scripting (XSS) vulnerability affecting ENOVIA Collaborative Industry |
| CVE-2024-6377 | 8.1 HIGH | URL redirection to untrusted site (open redirect) vulnerability affecting 3DPassport in 3D |
No comments yet