CVE-2024-7737: Dassault 3dswymer 3dexperience 2022

High severity, CVSS 8.7. EPSS: 0.4% chance of exploitation in the next 30 days.

A stored Cross-site Scripting (XSS) vulnerability affecting 3DSwym in 3DSwymer from Release 3DEXPERIENCE R2022x through Release 3DEXPERIENCE R2024x allows an attacker to execute arbitrary script code in user's browser session.

Affected products

  • Dassault 3dswymer 3dexperience 2022
  • Dassault 3dswymer 3dexperience 2023
  • Dassault 3dswymer 3dexperience 2024
  • Dassault Systèmes 3dswymer: from 3DEXPERIENCE R2022x Golden, up to and including 3DEXPERIENCE R2022x.FP.CFA.2424; from 3DEXPERIENCE R2023x Golden, up to and including 3DEXPERIENCE R2023x.FP.CFA.2428; from 3DEXPERIENCE R2024x Golden, up to and including 3DEXPERIENCE R2024x.FP.CFA.2424

Published 2024-09-19. Last modified 2026-06-17.