CVE-2025-27379
EUVD-2026-417222.01.2026, 02:15
A stored cross-site scripting (XSS) vulnerability in the BOM Viewer in Altium AES 7.0.3 allows an authenticated attacker to inject arbitrary JavaScript into the Description field of a schematic, which is executed when the BOM Viewer renders the affected content.
Affected Products (NVD)
| Vendor | Product | Version |
|---|---|---|
| altium | on-prem_enterprise_server | 7.0.3 ≤ 𝑥 < 7.0.6 |
𝑥
= Vulnerable software versions