CVE-2025-10551: ENOVIA Collaborative Industry Innovator XSS Vulnerability

CVE-2025-10551 identifies a Stored Cross-site Scripting (XSS) vulnerability in the Document Management feature of ENOVIA Collaborative Industry Innovator. This affects releases from 3DEXPERIENCE R2023x through R2025x, potentially allowing an attacker to execute arbitrary script code in a user’s browser session.

As a PLM Admin, I’m particularly interested in any dependencies or prerequisite updates required before applying the fix for CVE-2025-10551. We’re planning to test the Document Management functionality thoroughly post-patch, especially around user permissions and file access, to see if there are any unexpected behaviors.

From a solution architecture perspective, I’m evaluating the potential ripple effects of this update, particularly for any integrations interacting with the Document Management feature in our R2024x environment. Has anyone identified specific areas where customizations might conflict with the patch for CVE-2025-10551, or are there any known integration considerations?

Given this XSS vulnerability impacts R2023x through R2025x, I’m keen to understand if anyone on R2023x is considering this patch as part of a larger upgrade plan, rather than a standalone hotfix. We’re trying to determine if it’s better to roll this into a future migration to R2025x or address it independently first.

As a daily user of ENOVIA’s Document Management features, my main concern regarding CVE-2025-10551 is any potential downtime or change in workflow after the update. I’m hoping to hear about considerations for end-user communication and training if there are any noticeable UI or process impacts.