PT-2025-52428 · Foxit · Foxit Webplugins

Novee

+1

·

Published

2025-12-19

·

Updated

2025-12-19

·

CVE-2025-66500

CVSS v3.1

6.3

Medium

VectorAV:N/AC:L/PR:L/UI:R/S:U/C:H/I:L/A:N
Name of the Vulnerable Software and Affected Versions Foxit WebPlugins (affected versions not specified)
Description A stored cross-site scripting (XSS) issue exists due to a failure to validate the message origin within a postMessage handler. Specifically, the externalPath is directly assigned to a script source without proper validation, enabling an attacker to execute arbitrary JavaScript code when a specially crafted postMessage is received.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

XSS

Weakness Enumeration

Related Identifiers

CVE-2025-66500

Affected Products

Foxit Webplugins