CVE Vulnerabilities

CVE-2025-28244

Insecure Storage of Sensitive Information

Published: Jul 10, 2025 | Modified: Jul 17, 2025
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
RedHat/V2
RedHat/V3
Ubuntu

Insecure Permissions vulnerability in the Local Storage in Alteryx Server 2023.1.1.460 allows remote attackers to obtain valid user session tokens from localStorage, leading to account takeover

Weakness

The product stores sensitive information without properly limiting read or write access by unauthorized actors.

Affected Software

Name Vendor Start Version End Version
Alteryx_server Alteryx 2023.1.1.460 (including) 2023.1.1.460 (including)

References