CVE-2020-14425
Severity CVSS v4.0:
Pending analysis
Type:
Unavailable / Other
Publication date:
02/11/2020
Last modified:
12/11/2020
Description
Foxit Reader before 10.0 allows Remote Command Execution via the app.opencPDFWebPage JavsScript API. An attacker can execute local files and bypass the security dialog.
Impact
Base Score 3.x
7.80
Severity 3.x
HIGH
Base Score 2.0
6.80
Severity 2.0
MEDIUM
Vulnerable products and versions
| CPE | From | Up to |
|---|---|---|
| cpe:2.3:a:foxitsoftware:foxit_reader:*:*:*:*:*:*:*:* | 9.7.1 (including) | 10.0.0 (excluding) |
To consult the complete list of CPE names with products and versions, see this page



