PT-2026-3544 · Foxit · Foxit Esign

Novee

·

Published

2026-01-20

·

Updated

2026-02-04

·

CVE-2025-66523

CVSS v3.1

6.1

Medium

VectorAV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
Name of the Vulnerable Software and Affected Versions na1.foxitesign.foxit.com versions prior to 2026-01-16
Description The software embeds URL parameters directly into JavaScript code and HTML attributes without proper encoding or sanitization. This allows attackers to inject arbitrary scripts when an authenticated user visits a specially crafted link.
Recommendations Update to a version prior to 2026-01-16.

Fix

XSS

Weakness Enumeration

Related Identifiers

CVE-2025-66523

Affected Products

Foxit Esign