CVE-2025-28244
HIGHAlteryx Server <2023.1.1.460 - Info Disclosure
Title source: llmDescription
Insecure Permissions vulnerability in the Local Storage in Alteryx Server 2023.1.1.460 allows remote attackers to obtain valid user session tokens from localStorage, leading to account takeover
Scores
CVSS v3
8.8
EPSS
0.0014
EPSS Percentile
34.0%
Attack Vector
NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
Classification
CWE
CWE-922
Status
published
Affected Products (1)
alteryx/alteryx_server
Timeline
Published
Jul 10, 2025
Tracked Since
Feb 18, 2026