Insecure Permissions in Alteryx Server Product by Alteryx
CVE-2025-28244
8.8HIGH
What is CVE-2025-28244?
An insecure permissions vulnerability exists in Alteryx Server 2023.1.1.460, which enables remote attackers to exploit localStorage to gain unauthorized access to valid user session tokens. This vulnerability poses a significant risk, allowing adversaries to perform account takeover, jeopardizing user accounts and sensitive information.
