Vulnerability Details CVE-2018-13825
Insufficient input validation in the gridExcelExport functionality, in CA PPM 14.3 and below, 14.4, 15.1, 15.2 CP5 and below, and 15.3 CP2 and below, allows remote attackers to execute reflected cross-site scripting attacks.
Exploit prediction scoring system (EPSS) score
EPSS Score 0.002
EPSS Ranking 47.1%
CVSS Severity
CVSS v3 Score 6.1
CVSS v2 Score 4.3
Products affected by CVE-2018-13825
-
cpe:2.3:a:broadcom:project_portfolio_management:14.2
-
cpe:2.3:a:broadcom:project_portfolio_management:14.3
-
cpe:2.3:a:broadcom:project_portfolio_management:14.4
-
cpe:2.3:a:broadcom:project_portfolio_management:15.1
-
cpe:2.3:a:ca:project_portfolio_management:15.2
-
cpe:2.3:a:ca:project_portfolio_management:15.3