← Back

CVE-2025-4989

nvd nist
Published: May 30, 2025Modified: Jun 17, 2026Deferred

JSON object

Loading...
8.7
Vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:H/I:H/A:N
Exploitability: 2.3 / Impact: 5.8
Source: 3DS.Information-Security@3ds.com (Secondary)

Description

A stored Cross-site Scripting (XSS) vulnerability affecting Requirements in Product Manager from Release 3DEXPERIENCE R2022x through Release 3DEXPERIENCE R2025x allows an attacker to execute arbitrary script code in user's browser session.

References (1)

Source: 3DS.Information-Security@3ds.com

Timeline

No history available yet.