VYPR
Unrated severityNVD Advisory· Published Oct 13, 2025· Updated Oct 14, 2025

Stored Cross-site Scripting (XSS) vulnerability affecting Specification Management in ENOVIA Specification Manager from Release 3DEXPERIENCE R2023x through Release 3DEXPERIENCE R2025x

CVE-2025-10556

Description

A stored Cross-site Scripting (XSS) vulnerability affecting Specification Management in ENOVIA Specification Manager from Release 3DEXPERIENCE R2023x through Release 3DEXPERIENCE R2025x allows an attacker to execute arbitrary script code in user's browser session.

Affected products

1
  • Dassault Systèmes/ENOVIA Specification Managerv5
    Range: Release 3DEXPERIENCE R2023x Golden

Patches

0

No patches discovered yet.

Vulnerability mechanics

AI mechanics synthesis has not run for this CVE yet.

References

1

News mentions

0

No linked articles in our index yet.