CVE-2025-28244

I

nsecure Permissions vulnerability in the Local Storage in Alteryx Server 2023.1.1.460 allows remote attackers to obtain valid user session tokens from localStorage, leading to account takeover

References
Link Resource
https://alteryx.com Product
https://gist.github.com/DylanGrl/2771afe86bdd2665b83f28c1ff5c12eb Exploit Third Party Advisory Mitigation
Configurations

Configuration 1 (hide)

cpe:2.3:a:alteryx:alteryx_server:2023.1.1.460:*:*:*:*:*:*:*

History

17 Jul 2025, 00:57

Type Values Removed Values Added
First Time Alteryx alteryx Server
Alteryx
References () https://alteryx.com - () https://alteryx.com - Product
References () https://gist.github.com/DylanGrl/2771afe86bdd2665b83f28c1ff5c12eb - () https://gist.github.com/DylanGrl/2771afe86bdd2665b83f28c1ff5c12eb - Exploit, Third Party Advisory, Mitigation
CPE cpe:2.3:a:alteryx:alteryx_server:2023.1.1.460:*:*:*:*:*:*:*

11 Jul 2025, 14:15

Type Values Removed Values Added
CWE CWE-922
Summary
  • (es) La vulnerabilidad de permisos inseguros en el almacenamiento local en Alteryx Server 2023.1.1.460 permite a atacantes remotos obtener tokens de sesión de usuario válidos de localStorage, lo que lleva a la toma de control de la cuenta.
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 8.8

10 Jul 2025, 19:15

Type Values Removed Values Added
New CVE

Information

Published : 2025-07-10 19:15

Updated : 2025-07-17 00:57


NVD link : CVE-2025-28244

Mitre link : CVE-2025-28244

CVE.ORG link : CVE-2025-28244


JSON object : View

Products Affected
CWE
CWE-922

Insecure Storage of Sensitive Information