VYPR
Medium severity5.4NVD Advisory· Published May 17, 2024· Updated Apr 15, 2026

CVE-2023-5597

CVE-2023-5597

Description

Stored XSS in 3DDashboard in 3DSwymer (R2023x–R2024x) allows arbitrary script execution via crafted input.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

Stored XSS in 3DDashboard in 3DSwymer (R2023x–R2024x) allows arbitrary script execution via crafted input.

Vulnerability

CVE-2023-5597 is a stored Cross-site Scripting (XSS) vulnerability in the 3DDashboard component of 3DSwymer, affecting releases 3DEXPERIENCE R2023x through R2024x. The issue arises from insufficient input sanitization, allowing an attacker to inject malicious scripts that are stored and later executed in the context of other users' browsers.

Exploitation

To exploit the vulnerability, an attacker must have the ability to submit data to the 3DDashboard (e.g., via comments, posts, or configuration fields) that is not properly sanitized. When a legitimate user views the compromised dashboard page, the injected script executes in their browser session. No special network position is required; the attacker only needs a valid account with appropriate permissions to modify dashboard content.

Impact

Successful exploitation allows the attacker to execute arbitrary JavaScript in the victim's browser. This can lead to session hijacking, credential theft, defacement, or redirection to malicious sites. The CVSS v3 base score of 5.4 reflects a moderate severity due to the need for user interaction and the scope of impact (confidentiality and integrity).

Mitigation

Dassault Systèmes has addressed this vulnerability in a security advisory [1]. Users should apply the recommended patches or upgrade to a fixed release. No workarounds are publicly documented; all affected versions should be updated promptly.

AI Insight generated on May 20, 2026. Synthesized from this CVE's description and the cited reference URLs; citations are validated against the source bundle.

Affected products

3

Patches

0

No patches discovered yet.

Vulnerability mechanics

AI mechanics synthesis has not run for this CVE yet.

References

1

News mentions

0

No linked articles in our index yet.