Altium Forum Stored Cross-Site Scripting Vulnerability
Vulnerability
A stored cross-site scripting vulnerability has been identified in the Altium Forum. This issue arises from inadequate server-side input sanitization in forum post content, allowing authenticated attackers to inject arbitrary JavaScript. The injected scripts are executed when other users view the affected posts. Exploitation of this vulnerability requires user interaction to access the malicious forum post. Once executed, the attacker's payload runs in the context of the victim's authenticated Altium 365 session, potentially leading to unauthorized access to workspace data, including design files and workspace settings.
Impact
Exploitation allows injected JavaScript to execute in the context of the victim's Altium 365 session, potentially accessing sensitive workspace data such as design files and workspace settings.
Vulnerability Rating
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.
