CNNVD-202507-1519 Information

CNNVD ID

CNNVD-202507-1519

CVE-2025-28243

  • CNNVD Published: 2025-07-10

Description (Chinese)

Alteryx Server是Alteryx公司的一个云托管或自托管的应用程序。用于发布、共享和执行工作流。 Alteryx Server 2023.1.1.460版本存在安全漏洞,该漏洞源于pages组件可能允许通过特制脚本进行HTML注入。

Description (English)

Alteryx Server is a cloud-based or self-hosted application of Alteryx. For publication, sharing and implementation streams. Alteryx Server 2023.1.460 has a security loophole, which stems from the fact that the pages component may allow for HTML injection through specially made scripts.

Hazard Level

Medium

Vulnerability Type

跨站脚本

Affected Vendor

Alteryx

Published

2025-07-10

Last Modified

2026-02-24

References

https://alteryx.com https://gist.github.com/DylanGrl/fbe4cc8eaf2b95147069c82b39be59b0 https://nvd.nist.gov/vuln/detail/CVE-2025-28243

Patch

https://help.alteryx.com/current/en/server.html#server-7112146

Share on: