CVE-2024-7939: 3ds 3dexperience

Medium severity, CVSS 5.4. EPSS: 0.3% chance of exploitation in the next 30 days.

A stored Cross-site Scripting (XSS) vulnerability affecting 3DSwym in 3DSwymer on Release 3DEXPERIENCE R2024x allows an attacker to execute arbitrary script code in user's browser session.

Affected products

  • 3ds 3dexperience: version r2024x only

Published 2024-09-02. Last modified 2026-06-17.