HTML injection in Project Release in Altium Enterprise Server (AES) 7.0.3 on all platforms allows an authenticated attacker to execute arbitrary JavaScript in the victim’s browser via crafted HTML content.
References
| Link | Resource |
|---|---|
| https://www.altium.com/platform/security-compliance/security-advisories | Vendor Advisory |
Configurations
History
26 Feb 2026, 21:23
| Type | Values Removed | Values Added |
|---|---|---|
| CPE | cpe:2.3:a:altium:on-prem_enterprise_server:*:*:*:*:*:*:*:* | |
| References | () https://www.altium.com/platform/security-compliance/security-advisories - Vendor Advisory | |
| First Time |
Altium
Altium on-prem Enterprise Server |
22 Jan 2026, 02:15
| Type | Values Removed | Values Added |
|---|---|---|
| New CVE |
Information
Published : 2026-01-22 02:15
Updated : 2026-02-26 21:23
NVD link : CVE-2025-27380
Mitre link : CVE-2025-27380
CVE.ORG link : CVE-2025-27380
JSON object : View
Products Affected
altium
- on-prem_enterprise_server
CWE
CWE-79
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
