CVE-2021-45978

Severity CVSS v4.0:
Pending analysis
Type:
CWE-78 OS Command Injections
Publication date:
04/01/2022
Last modified:
12/07/2022

Description

Foxit PDF Reader and PDF Editor before 11.1 on macOS allow remote attackers to execute arbitrary code via xfa.host.gotoURL in the XFA API.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:foxit:pdf_editor:*:*:*:*:*:*:*:* 11.1 (excluding)
cpe:2.3:a:foxit:pdf_reader:*:*:*:*:*:*:*:* 11.1 (excluding)
cpe:2.3:o:apple:macos:-:*:*:*:*:*:*:*