CVE-2026-1009 (CNNVD-202601-2693)
中文标题:
Altium 365 安全漏洞
英文标题:
Stored Cross-Site Scripting in Altium Forum Leading to Cross-Customer Data Exposure
漏洞描述
中文描述:
Altium 365是美国Altium公司的一个产品设计和开发平台。 Altium 365存在安全漏洞,该漏洞源于论坛帖子内容缺少服务器端输入清理,可能导致存储型跨站脚本攻击。
英文描述:
A stored cross-site scripting (XSS) vulnerability exists in the Altium Forum due to missing server-side input sanitization in forum post content. An authenticated attacker can inject arbitrary JavaScript into forum posts, which is stored and executed when other users view the affected post. Successful exploitation allows the attacker’s payload to execute in the context of the victim’s authenticated Altium 365 session, enabling unauthorized access to workspace data, including design files and workspace settings. Exploitation requires user interaction to view a malicious forum post.
CWE类型:
标签:
受影响产品
| 厂商 | 产品 | 版本 | 版本范围 | 平台 | CPE |
|---|---|---|---|---|---|
| Altium | Altium Forum (Altium 365) | unspecified | - | - |
cpe:2.3:a:altium:altium_forum_(altium_365):unspecified:*:*:*:*:*:*:*
|
| altium | altium_live | 1.2.2 | - | - |
cpe:2.3:a:altium:altium_live:1.2.2:*:*:*:*:*:*:*
|
解决方案
中文解决方案:
英文解决方案:
临时解决方案:
参考链接
cve.org
CVSS评分详情
3.1 (cna)
CRITICALCVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:H/I:H/A:H
时间信息
利用信息
数据源详情
| 数据源 | 记录ID | 版本 | 提取时间 |
|---|---|---|---|
| CVE | cve_CVE-2026-1009 |
2026-01-16 02:21:12 | 2026-01-16 02:44:24 |
| NVD | nvd_CVE-2026-1009 |
2026-01-17 03:00:05 | 2026-01-17 06:00:15 |
| CNNVD | cnnvd_CNNVD-202601-2693 |
2026-01-26 02:10:01 | 2026-01-25 18:11:47 |
版本与语言
安全公告
变更历史
查看详细变更
- vulnerability_type: 未提取 -> 其他
- cnnvd_id: 未提取 -> CNNVD-202601-2693
- data_sources: ['cve', 'nvd'] -> ['cnnvd', 'cve', 'nvd']
查看详细变更
- affected_products_count: 1 -> 2
查看详细变更
- data_sources: ['cve'] -> ['cve', 'nvd']