Vulnerability Description
HTML injection in Project Release in Altium Enterprise Server (AES) 7.0.3 on all platforms allows an authenticated attacker to execute arbitrary JavaScript in the victim’s browser via crafted HTML content.
CVSS Score
HIGH
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Altium | On-Prem Enterprise Server | >= 7.0.3, < 7.0.6 |
Related Weaknesses (CWE)
References
FAQ
What is CVE-2025-27380?
CVE-2025-27380 is a vulnerability with a CVSS score of 7.6 (HIGH). HTML injection in Project Release in Altium Enterprise Server (AES) 7.0.3 on all platforms allows an authenticated attacker to execute arbitrary JavaScript in the victim’s browser via crafted HTML con...
How severe is CVE-2025-27380?
CVE-2025-27380 has been rated HIGH with a CVSS base score of 7.6/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2025-27380?
Check the references section above for vendor advisories and patch information. Affected products include: Altium On-Prem Enterprise Server.