HTML Injection Vulnerability in Alteryx Server
CVE-2025-28243

8HIGH

Key Information:

Vendor

Alteryx

Vendor
CVE Published:
10 July 2025

What is CVE-2025-28243?

An HTML injection vulnerability exists in Alteryx Server v.2023.1.1.460, which allows attackers to inject malicious HTML scripts through crafted inputs. This vulnerability poses a significant risk as it can lead to unauthorized access or manipulation of user-facing web pages, potentially compromising sensitive data and user safety.

References

CVSS V3.1

Score:
8
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
High
Privileges Required:
None
User Interaction:
Required
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.
CVE-2025-28243 : HTML Injection Vulnerability in Alteryx Server