PT-2025-52430 · Foxit · Foxit Pdf Online

Novee

+1

·

Published

2025-12-19

·

Updated

2025-12-19

·

CVE-2025-66502

CVSS v3.1

6.3

Medium

VectorAV:N/AC:L/PR:L/UI:R/S:U/C:H/I:L/A:N
Name of the Vulnerable Software and Affected Versions Foxit PDF Online (affected versions not specified)
Description A stored cross-site scripting (XSS) issue exists in the Page Templates feature of pdfonline.foxit.com. A malicious payload can be stored as a template name. This payload is then rendered into the Document Object Model (DOM) without sufficient sanitization, leading to script execution whenever the affected PDF document is loaded. The vulnerability involves storing a crafted payload, which is then executed. The affected area is the Page Templates feature.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

XSS

Weakness Enumeration

Related Identifiers

CVE-2025-66502

Affected Products

Foxit Pdf Online