Stored Cross-Site Scripting Vulnerability in Project Portfolio Manager by Dassault Systèmes
CVE-2025-4987
What is CVE-2025-4987?
A stored Cross-site Scripting (XSS) vulnerability has been identified in the Opportunity Management component of the Project Portfolio Manager, affecting versions from 3DEXPERIENCE R2023x to R2025x. This flaw enables attackers to inject and execute arbitrary script code within the browser session of an unsuspecting user. As a result, it may lead to unauthorized data access or manipulation, posing a risk to user data integrity and security.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.
Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.
Affected Version(s)
Project Portfolio Manager Release 3DEXPERIENCE R2023x Golden
Project Portfolio Manager Release 3DEXPERIENCE R2024x Golden
Project Portfolio Manager Release 3DEXPERIENCE R2025x Golden
References
CVSS V3.1
Timeline
Vulnerability published
Vulnerability Reserved
