CVE-2025-27380

Published Jan 22, 2026

Last updated 4 months ago

Overview

Description
HTML injection in Project Release in Altium Enterprise Server (AES) 7.0.3 on all platforms allows an authenticated attacker to execute arbitrary JavaScript in the victim’s browser via crafted HTML content.
Source
4760f414-e1ae-4ff1-bdad-c7a9c3538b79
NVD status
Analyzed
Products
on-prem_enterprise_server

Risk scores

CVSS 3.1

Type
Secondary
Base score
7.6
Impact score
4.7
Exploitability score
2.3
Vector string
CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:H/I:L/A:N
Severity
HIGH

Weaknesses

4760f414-e1ae-4ff1-bdad-c7a9c3538b79
CWE-79

Social media

Hype score
Not currently trending

Configurations

References

Sources include official advisories and independent security research.