← Back

CVE-2025-4987

nvd nist
Published: Jun 16, 2025Modified: Jun 17, 2026Deferred

JSON object

Loading...
8.7
Vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:H/I:H/A:N
Exploitability: 2.3 / Impact: 5.8
Source: 3DS.Information-Security@3ds.com (Secondary)

Description

A stored Cross-site Scripting (XSS) vulnerability affecting Opportunity Management in Project Portfolio Manager from Release 3DEXPERIENCE R2023x through Release 3DEXPERIENCE R2025x allows an attacker to execute arbitrary script code in user's browser session.

References (1)

Source: 3DS.Information-Security@3ds.com

Timeline

No history available yet.