Vulnerability Details CVE-2018-13825
Insufficient input validation in the gridExcelExport functionality, in CA PPM 14.3 and below, 14.4, 15.1, 15.2 CP5 and below, and 15.3 CP2 and below, allows remote attackers to execute reflected cross-site scripting attacks.
Exploit prediction scoring system (EPSS) score
EPSS Score 0.009
EPSS Ranking 54.9%
CVSS Severity
CVSS v3 Score 6.1
CVSS v2 Score 4.3
Products affected by CVE-2018-13825
-
cpe:2.3:a:broadcom:project_portfolio_management:14.2
-
cpe:2.3:a:broadcom:project_portfolio_management:14.3
-
cpe:2.3:a:broadcom:project_portfolio_management:14.4
-
cpe:2.3:a:broadcom:project_portfolio_management:15.1
-
cpe:2.3:a:ca:project_portfolio_management:15.2
-
cpe:2.3:a:ca:project_portfolio_management:15.3