CVE-2025-4984

HIGH

Dassault Systmes City Referential Manager Release 3DEXPERIENCE R2025x - Stored Cross-Site Scripting

Title source: llm
STIX 2.1

Exploitation Summary

EIP tracks 1 public exploit for CVE-2025-4984. PoCs published by Yuri08loveElaina.

AI-analyzed exploit summary This repository contains a functional exploit for CVE-2025-49844, targeting a Use-After-Free (UAF) vulnerability in the Redis Lua interpreter. The exploit includes techniques for ASLR bypass, DEP/NX bypass via ROP, heap spraying, and arbitrary shellcode execution.

Description

A stored Cross-site Scripting (XSS) vulnerability affecting City Discover in City Referential Manager on Release 3DEXPERIENCE R2025x allows an attacker to execute arbitrary script code in user's browser session.

Exploits (1)

github WORKING POC 64 stars
by Yuri08loveElaina · pythonpoc
https://github.com/Yuri08loveElaina/CVE-2025-49844

This repository contains a functional exploit for CVE-2025-49844, targeting a Use-After-Free (UAF) vulnerability in the Redis Lua interpreter. The exploit includes techniques for ASLR bypass, DEP/NX bypass via ROP, heap spraying, and arbitrary shellcode execution.

Classification
Working Poc 95%
Attack Type
Rce
Complexity
Complex
Reliability
Reliable
Target: Redis 7.2.x before 7.2.11, Redis 7.4.x before 7.4.6, Redis 8.0.x before 8.0.4, Redis 8.2.x before 8.2.2
Auth required
Prerequisites: Python 3.6+ · Redis server with vulnerable version · Network access to target Redis instance · Optional Redis password if authentication is enabled
devstral-2 · analyzed Feb 19, 2026 Full analysis →

References (1)

Core 1
Core References

Scores

CVSS v3 8.7
EPSS 0.0026
EPSS Percentile 17.2%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:H/I:H/A:N

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact total

Details

CWE
CWE-79
Status published
Products (1)
Dassault Systèmes/City Referential Manager Release 3DEXPERIENCE R2025x Golden
Published May 30, 2025
Tracked Since Feb 18, 2026