CVE-2025-10554

Publication date

2025-11-24 15:31:39

Family

3DS

State

PUBLISHED

Description

A stored Cross-site Scripting (XSS) vulnerability affecting Requirements in ENOVIA Product Manager from Release 3DEXPERIENCE R2023x through Release 3DEXPERIENCE R2025x allows an attacker to execute arbitrary script code in users browser session.