HTML injection in Project Release in Altium Enterprise Server (AES) 7.0.3 on all platforms allows an authenticated attacker to execute arbitrary JavaScript in the victim’s browser via crafted HTML content.
Metrics
Affected Vendors & Products
Advisories
No advisories yet.
Fixes
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
References
History
Thu, 22 Jan 2026 02:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | HTML injection in Project Release in Altium Enterprise Server (AES) 7.0.3 on all platforms allows an authenticated attacker to execute arbitrary JavaScript in the victim’s browser via crafted HTML content. | |
| Title | HTML Injection Leading to Script Execution in Altium Enterprise Server | |
| Weaknesses | CWE-79 | |
| References |
| |
| Metrics |
cvssV3_1
|
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: Altium
Published:
Updated: 2026-01-22T01:29:16.784Z
Reserved: 2025-02-23T21:02:12.105Z
Link: CVE-2025-27380
No data.
Status : Received
Published: 2026-01-22T02:15:51.310
Modified: 2026-01-22T02:15:51.310
Link: CVE-2025-27380
No data.
OpenCVE Enrichment
No data.
Weaknesses