CVE-2025-4984
HIGHDassault Systmes City Referential Manager Release 3DEXPERIENCE R2025x - Stored Cross-Site Scripting
Title source: llmExploitation Summary
EIP tracks 1 public exploit for CVE-2025-4984. PoCs published by Yuri08loveElaina.
AI-analyzed exploit summary This repository contains a functional exploit for CVE-2025-49844, targeting a Use-After-Free (UAF) vulnerability in the Redis Lua interpreter. The exploit includes techniques for ASLR bypass, DEP/NX bypass via ROP, heap spraying, and arbitrary shellcode execution.
Description
A stored Cross-site Scripting (XSS) vulnerability affecting City Discover in City Referential Manager on Release 3DEXPERIENCE R2025x allows an attacker to execute arbitrary script code in user's browser session.
Exploits (1)
This repository contains a functional exploit for CVE-2025-49844, targeting a Use-After-Free (UAF) vulnerability in the Redis Lua interpreter. The exploit includes techniques for ASLR bypass, DEP/NX bypass via ROP, heap spraying, and arbitrary shellcode execution.
References (1)
Scores
CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:H/I:H/A:N