CVE-2021-27517

Severity CVSS v4.0:
Pending analysis
Type:
CWE-79 Cross-Site Scripting (XSS)
Publication date:
20/07/2021
Last modified:
29/07/2021

Description

Foxit PDF SDK For Web through 7.5.0 allows XSS. There is arbitrary JavaScript code execution in the browser if a victim uploads a malicious PDF document containing embedded JavaScript code that abuses app.alert (in the Acrobat JavaScript API).

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:foxit:phantompdf:*:*:*:*:*:*:*:* 9.7.5.29616 (including)
cpe:2.3:a:foxit:phantompdf:*:*:*:*:*:*:*:* 10.0.0.0 (including) 10.1.3.37598 (including)
cpe:2.3:a:foxit:reader:*:*:*:*:*:*:*:* 10.1.3.37598 (including)


References to Advisories, Solutions, and Tools