PT-2025-50624 · Foxit · Foxit Pdf Editor+1
Published
2025-12-11
·
Updated
2025-12-15
·
CVE-2025-59803
CVSS v3.1
5.3
Medium
| Vector | AV:N/AC:H/PR:N/UI:R/S:U/C:N/I:H/A:N |
Name of the Vulnerable Software and Affected Versions
Foxit PDF Editor and Reader versions prior to 2025.2.1
Foxit PDF Reader versions prior to 2025.2.1
Foxit PDF Editor versions prior to 2025.2.1
Description
The software is susceptible to signature spoofing through the use of triggers. An attacker can embed triggers, such as JavaScript, within a PDF document. These triggers execute during the signing process. While the document initially appears normal to the signer, the triggers can modify content on other pages or optional content layers after the signature is applied, without providing a warning. This modification can result in a signed PDF differing from the version the signer reviewed, compromising the integrity of the digital signature.
Recommendations
Update Foxit PDF Editor and Reader to version 2025.2.1 or later.
Update Foxit PDF Editor to version 14.0.1 or later.
Update Foxit PDF Reader to version 13.2.1 or later.
Fix
Improper Verification of Cryptographic Signature
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Foxit Pdf Editor
Foxit Pdf Reader