CVE-2025-27380
7.6Altium · Enterprise Server (AES)
Altium Enterprise Server (AES) 7.0.3 through 7.0.5 is vulnerable to HTML injection via Project Release, allowing authenticated attackers to execute arbitrary JavaScript in a victim browser.
Executive summary
An authenticated HTML injection vulnerability in Altium Enterprise Server 7 allows attackers to execute arbitrary JavaScript in a victim's browser, posing a significant risk of session compromise.
Vulnerability
The software fails to properly neutralize input during web page generation, specifically within the Project Release component. This allows an authenticated attacker to inject malicious HTML and execute arbitrary JavaScript in the context of a victim's session.
Business impact
Successful exploitation of this cross-site scripting vulnerability could allow an attacker to perform actions on behalf of authenticated users, potentially leading to unauthorized data access or session hijacking. Given the CVSS score of 7.6, this is classified as a high-severity issue that could compromise the integrity of internal design documentation and project workflows.
Remediation
Immediate Action: Review the official Altium security advisory portal and apply the latest available updates to remediate the vulnerability.
Proactive Monitoring: Monitor web server access logs for anomalous requests containing script tags or encoded HTML payloads directed at the Project Release module.
Compensating Controls: Deploy a Web Application Firewall (WAF) with strict cross-site scripting filtering enabled to detect and block malicious injection attempts.
Exploitation status
Public Exploit Available: No
Analyst recommendation
Organizations utilizing Altium Enterprise Server 7 should prioritize identifying affected instances and verifying the availability of vendor patches. Because this flaw allows for arbitrary script execution, it is imperative to restrict access to the Project Release functionality to authorized users only until a patch is successfully deployed.