TROYANOSYVIRUS
Back to CVEs

CVE-2025-28244

HIGH
8.8

Description

Insecure Permissions vulnerability in the Local Storage in Alteryx Server 2023.1.1.460 allows remote attackers to obtain valid user session tokens from localStorage, leading to account takeover

CVE Details

CVSS v3.1 Score8.8
SeverityHIGH
CVSS VectorCVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
Attack VectorNETWORK
ComplexityLOW
Privileges RequiredNONE
User InteractionREQUIRED
Published7/10/2025
Last Modified7/17/2025
Sourcenvd
Honeypot Sightings0

Affected Products

alteryx:alteryx_server

Weaknesses (CWE)

CWE-922

IOC Correlations

No correlations recorded

This product uses data from the NVD API but is not endorsed or certified by the NVD.