« Volver al listado

CVE-2023-3588

Estado: ModificadaMedia (5.4)—

A stored Cross-site Scripting (XSS) vulnerability affecting Teamwork Cloud from No Magic Release 2021x through No Magic Release 2022x allows an attacker to execute arbitrary script code.

CVSS

Probabilidad de explotación (EPSS)

EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).

Tecnologías afectadas (1)

CWE

Referencias

JSON original (NVD)

Mostrar
{
  "id": "CVE-2023-3588",
  "cveTags": [],
  "metrics": {
    "ssvcV203": [
      {
        "source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
        "ssvcData": {
          "id": "CVE-2023-3588",
          "role": "CISA Coordinator",
          "options": [
            {
              "exploitation": "none"
            },
            {
              "automatable": "no"
            },
            {
              "technicalImpact": "partial"
            }
          ],
          "version": "2.0.3",
          "timestamp": "2024-07-16T18:38:50.525810Z"
        }
      }
    ],
    "cvssMetricV31": [
      {
        "type": "Secondary",
        "source": "3DS.Information-Security@3ds.com",
        "cvssData": {
          "scope": "CHANGED",
          "version": "3.1",
          "baseScore": 5.4,
          "attackVector": "NETWORK",
          "baseSeverity": "MEDIUM",
          "vectorString": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N",
          "integrityImpact": "LOW",
          "userInteraction": "REQUIRED",
          "attackComplexity": "LOW",
          "availabilityImpact": "NONE",
          "privilegesRequired": "LOW",
          "confidentialityImpact": "LOW"
        },
        "impactScore": 2.7,
        "exploitabilityScore": 2.3
      },
      {
        "type": "Primary",
        "source": "nvd@nist.gov",
        "cvssData": {
          "scope": "CHANGED",
          "version": "3.1",
          "baseScore": 5.4,
          "attackVector": "NETWORK",
          "baseSeverity": "MEDIUM",
          "vectorString": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N",
          "integrityImpact": "LOW",
          "userInteraction": "REQUIRED",
          "attackComplexity": "LOW",
          "availabilityImpact": "NONE",
          "privilegesRequired": "LOW",
          "confidentialityImpact": "LOW"
        },
        "impactScore": 2.7,
        "exploitabilityScore": 2.3
      }
    ]
  },
  "affected": [
    {
      "source": "3DS.Information-Security@3ds.com",
      "affectedData": [
        {
          "vendor": "Dassault Systèmes",
          "product": "Teamwork Cloud - Business Edition",
          "versions": [
            {
              "status": "affected",
              "version": "No Magic Release 2021x Golden",
              "versionType": "custom",
              "lessThanOrEqual": "No Magic Release 2021x Refresh2"
            },
            {
              "status": "affected",
              "version": "No Magic Release 2022x Golden",
              "versionType": "custom",
              "lessThanOrEqual": "No Magic Release 2022x Refresh2"
            }
          ],
          "defaultStatus": "unaffected"
        },
        {
          "vendor": "Dassault Systèmes",
          "product": "Teamwork Cloud - Enterprise Edition",
          "versions": [
            {
              "status": "affected",
              "version": "No Magic Release 2021x Golden",
              "versionType": "custom",
              "lessThanOrEqual": "No Magic Release 2021x Refresh2"
            },
            {
              "status": "affected",
              "version": "No Magic Release 2022x Golden",
              "versionType": "custom",
              "lessThanOrEqual": "No Magic Release 2022x Refresh2"
            }
          ],
          "defaultStatus": "unaffected"
        },
        {
          "vendor": "Dassault Systèmes",
          "product": "Teamwork Cloud - Business Pro Edition",
          "versions": [
            {
              "status": "affected",
              "version": "No Magic Release 2021x Golden",
              "versionType": "custom",
              "lessThanOrEqual": "No Magic Release 2021x Refresh2"
            },
            {
              "status": "affected",
              "version": "No Magic Release 2022x Golden",
              "versionType": "custom",
              "lessThanOrEqual": "No Magic Release 2022x Refresh2"
            }
          ],
          "defaultStatus": "unaffected"
        },
        {
          "vendor": "Dassault Systèmes",
          "product": "Teamwork Cloud - Standard Edition",
          "versions": [
            {
              "status": "affected",
              "version": "No Magic Release 2021x Golden",
              "versionType": "custom",
              "lessThanOrEqual": "No Magic Release 2021x Refresh2"
            },
            {
              "status": "affected",
              "version": "No Magic Release 2022x Golden",
              "versionType": "custom",
              "lessThanOrEqual": "No Magic Release 2022x Refresh2"
            }
          ],
          "defaultStatus": "unaffected"
        }
      ]
    }
  ],
  "published": "2023-09-13T19:15:07.787",
  "references": [
    {
      "url": "https://www.3ds.com/vulnerability/advisories",
      "tags": [
        "Vendor Advisory"
      ],
      "source": "3DS.Information-Security@3ds.com"
    },
    {
      "url": "https://www.3ds.com/vulnerability/advisories",
      "tags": [
        "Vendor Advisory"
      ],
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    }
  ],
  "vulnStatus": "Modified",
  "weaknesses": [
    {
      "type": "Secondary",
      "source": "3DS.Information-Security@3ds.com",
      "description": [
        {
          "lang": "en",
          "value": "CWE-79"
        }
      ]
    },
    {
      "type": "Primary",
      "source": "nvd@nist.gov",
      "description": [
        {
          "lang": "en",
          "value": "CWE-79"
        }
      ]
    }
  ],
  "descriptions": [
    {
      "lang": "en",
      "value": "A stored Cross-site Scripting (XSS) vulnerability affecting Teamwork Cloud from No Magic Release 2021x through No Magic Release 2022x allows an attacker to execute arbitrary script code."
    },
    {
      "lang": "es",
      "value": "Una vulnerabilidad de Cross-Site Scripting (XSS) almacenado que afecta a Teamwork Cloud desde No Magic Release 2021x hasta No Magic Release 2022x permite a un atacante ejecutar scripts de comandos arbitrarios."
    }
  ],
  "lastModified": "2026-06-17T06:14:24.800",
  "configurations": [
    {
      "nodes": [
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:a:3ds:teamwork_cloud_no_magic_release:2021x:*:*:*:business:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "E3465527-6062-4671-932F-5AC8CB6CAE76"
            },
            {
              "criteria": "cpe:2.3:a:3ds:teamwork_cloud_no_magic_release:2021x:*:*:*:business_pro:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "2E7ADE53-CDAC-4135-A452-C81289828F47"
            },
            {
              "criteria": "cpe:2.3:a:3ds:teamwork_cloud_no_magic_release:2021x:*:*:*:enterprise:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "CC55035D-9D34-4B26-9B89-BEF735AF0465"
            },
            {
              "criteria": "cpe:2.3:a:3ds:teamwork_cloud_no_magic_release:2021x:*:*:*:standard:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "D1BBE2EE-6042-4F9C-A423-5BF8C58757F0"
            },
            {
              "criteria": "cpe:2.3:a:3ds:teamwork_cloud_no_magic_release:2022x:*:*:*:business:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "CBED6A07-495A-45E2-8670-6D0093E4E332"
            },
            {
              "criteria": "cpe:2.3:a:3ds:teamwork_cloud_no_magic_release:2022x:*:*:*:business_pro:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "5F10E179-1EAA-4C34-96DE-197F82EE2CA1"
            },
            {
              "criteria": "cpe:2.3:a:3ds:teamwork_cloud_no_magic_release:2022x:*:*:*:enterprise:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "BFEB98EE-3955-4A58-ACEE-59DDE97AFA34"
            },
            {
              "criteria": "cpe:2.3:a:3ds:teamwork_cloud_no_magic_release:2022x:*:*:*:standard:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "18C200BF-E20D-4FB7-83EA-24DBFA01D0BB"
            }
          ],
          "operator": "OR"
        }
      ]
    }
  ],
  "sourceIdentifier": "3DS.Information-Security@3ds.com"
}