Vulnerabilities > CA > Project Portfolio Management > Medium

DATE CVE VULNERABILITY TITLE RISK
2018-08-30 CVE-2018-13825 Cross-site Scripting vulnerability in multiple products
Insufficient input validation in the gridExcelExport functionality, in CA PPM 14.3 and below, 14.4, 15.1, 15.2 CP5 and below, and 15.3 CP2 and below, allows remote attackers to execute reflected cross-site scripting attacks.
network
low complexity
ca broadcom CWE-79
6.1