Описание
A stored Cross-site Scripting (XSS) vulnerability affecting Service Items Management in Service Process Engineer from Release 3DEXPERIENCE R2024x through Release 3DEXPERIENCE R2025x allows an attacker to execute arbitrary script code in user's browser session.
EPSS
8.7 High
CVSS3
Дефекты
Связанные уязвимости
A stored Cross-site Scripting (XSS) vulnerability affecting Service Items Management in Service Process Engineer from Release 3DEXPERIENCE R2024x through Release 3DEXPERIENCE R2025x allows an attacker to execute arbitrary script code in user's browser session.
Уязвимость компонента Items Management Service программного решения для проектирования и оптимизации сервисных процессов Service Process Engineer, позволяющая нарушителю проводить межсайтовые сценарные атаки
EPSS
8.7 High
CVSS3