Stored Cross-Site Scripting Vulnerability in Project Portfolio Manager by Dassault Systèmes
CVE-2025-4987
8.7HIGH
What is CVE-2025-4987?
A stored Cross-site Scripting (XSS) vulnerability has been identified in the Opportunity Management component of the Project Portfolio Manager, affecting versions from 3DEXPERIENCE R2023x to R2025x. This flaw enables attackers to inject and execute arbitrary script code within the browser session of an unsuspecting user. As a result, it may lead to unauthorized data access or manipulation, posing a risk to user data integrity and security.
Affected Version(s)
Project Portfolio Manager Release 3DEXPERIENCE R2023x Golden
Project Portfolio Manager Release 3DEXPERIENCE R2024x Golden
Project Portfolio Manager Release 3DEXPERIENCE R2025x Golden