Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
Reflected Cross-site Scripting (XSS) vulnerability affecting 3DSwymer from Release 3DEXPERIENCE R2022x through Release 3DEXPERIENCE R2024x
Vulnerability Description
A reflected Cross-site Scripting (XSS) vulnerability affecting 3DSwymer from Release 3DEXPERIENCE R2022x through Release 3DEXPERIENCE R2024x allows an attacker to execute arbitrary script code in user's browser session.
CVSS Information
CVSS:3.1/AV:N/AC:H/PR:L/UI:R/S:C/C:H/I:H/A:N
Vulnerability Type
在Web页面生成时对输入的转义处理不恰当(跨站脚本)
Vulnerability Title
Dassault Systèmes 3DEXPERIENCE 安全漏洞
Vulnerability Description
Dassault Systèmes 3DEXPERIENCE是法国达索系统(Dassault Systèmes)公司的一种业务与创新平台。 Dassault Systèmes 3DEXPERIENCE R2022x版本至R2024x版本存在安全漏洞,该漏洞源于3DPassport存在URL重定向到不受信任站点漏洞,允许攻击者通过精心设计的UR将用户重定向到任意网站。
CVSS Information
N/A
Vulnerability Type
N/A