Dassault Systèmes ENOVIA Specification Manager是法国达索系统(Dassault Systèmes)公司的一个用于创建、管理和协作产品规格的应用模块。 Dassault Systèmes ENOVIA Specification Manager R2022x版本至3DEXPERIENCE R2025x版本存在安全漏洞,该漏洞源于Issue Management存在存储型跨站脚本,可能导致攻击者在用户浏览器会话中执行任意脚本代码。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| Dassault Systèmes | ENOVIA Collaborative Industry Innovator | Release 3DEXPERIENCE R2022x Golden ~ Release 3DEXPERIENCE R2022x.FP.CFA.2513 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2025-9976 | 9.0 CRITICAL | OS Command Injection vulnerability affecting Station Launcher App in 3DEXPERIENCE platform |
| CVE-2025-10558 | 8.7 HIGH | Stored Cross-site Scripting (XSS) vulnerability affecting 3DSearch in 3DSwymer on Release |
| CVE-2025-10556 | 8.7 HIGH | Stored Cross-site Scripting (XSS) vulnerability affecting Specification Management in ENOV |
| CVE-2025-10552 | 8.7 HIGH | Stored Cross-site Scripting (XSS) vulnerability affecting 3DSwym in 3DSwymer on Release 3D |
No comments yet