VYPR
Unrated severityNVD Advisory· Published May 19, 2023· Updated Feb 12, 2025

Reflected Cross-site Scripting (XSS) vulnerability affecting Release 3DEXPERIENCE R2018x through Release 3DEXPERIENCE R2023x

CVE-2023-1996

Description

A reflected XSS vulnerability in 3DEXPERIENCE from R2018x through R2023x allows remote attackers to execute arbitrary script code.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

A reflected XSS vulnerability in 3DEXPERIENCE from R2018x through R2023x allows remote attackers to execute arbitrary script code.

Vulnerability

A reflected Cross-site Scripting (XSS) vulnerability exists in Release 3DEXPERIENCE versions R2018x through R2023x. The vulnerability allows an attacker to inject arbitrary script code via a crafted request, which is then reflected back to the user without proper sanitization [1].

Exploitation

An attacker can exploit this vulnerability by crafting a malicious URL or input that, when processed by the 3DEXPERIENCE application, is reflected in the response. No authentication is required, and the attack relies on the victim clicking a specially crafted link or visiting a malicious site that triggers the vulnerable endpoint [1].

Impact

Successful exploitation allows the attacker to execute arbitrary script code in the context of the victim's browser session. This can lead to session hijacking, defacement, or theft of sensitive data within the scope of the 3DEXPERIENCE application [1].

Mitigation

Dassault Systèmes has not yet disclosed a fix in the available references. Users should apply any patches or workarounds provided in future security advisories from the vendor [1].

AI Insight generated on May 25, 2026. Synthesized from this CVE's description and the cited reference URLs; citations are validated against the source bundle.

Affected products

2
  • Dassault Systèmes/3DEXPERIENCEllm-fuzzy2 versions
    R2018x through R2023x+ 1 more
    • (no CPE)range: R2018x through R2023x
    • (no CPE)range: Release 3DEXPERIENCE R2018x - All levels

Patches

0

No patches discovered yet.

Vulnerability mechanics

AI mechanics synthesis has not run for this CVE yet.

References

1

News mentions

0

No linked articles in our index yet.