CVE-2025-27379: Stored Cross-Site Scripting in AES BOM Viewer
A stored cross-site scripting (XSS) vulnerability in the BOM Viewer in Altium AES 7.0.3 allows an authenticated attacker to inject arbitrary JavaScript into the Description field of a schematic, which is executed when the BOM Viewer renders the affected content.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-27379?
CVE-2025-27379 is classified as a stored cross-site scripting (XSS) vulnerability, which can pose significant security risks.
How do I fix CVE-2025-27379?
To mitigate CVE-2025-27379, ensure that your Altium AES software is updated to the latest version that addresses this vulnerability.
Who is affected by CVE-2025-27379?
Users of the Altium AES version 7.0.3 are primarily affected by CVE-2025-27379.
What can an attacker do with CVE-2025-27379?
An authenticated attacker can inject arbitrary JavaScript into the Description field in the BOM Viewer, potentially leading to account compromise or data theft.
Is there a workaround for CVE-2025-27379?
As of now, the best course of action is to update to the patched version of Altium AES to eliminate risks associated with CVE-2025-27379.