Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-gh4f-wqp7-vmm2

Опубликовано: 24 мая 2022
Источник: github
Github: Не прошло ревью

Описание

Foxit PDF SDK For Web through 7.5.0 allows XSS. There is arbitrary JavaScript code execution in the browser if a victim uploads a malicious PDF document containing embedded JavaScript code that abuses app.alert (in the Acrobat JavaScript API).

Foxit PDF SDK For Web through 7.5.0 allows XSS. There is arbitrary JavaScript code execution in the browser if a victim uploads a malicious PDF document containing embedded JavaScript code that abuses app.alert (in the Acrobat JavaScript API).

EPSS

Процентиль: 64%
0.00471
Низкий

Дефекты

CWE-79

Связанные уязвимости

CVSS3: 6.1
nvd
больше 4 лет назад

Foxit PDF SDK For Web through 7.5.0 allows XSS. There is arbitrary JavaScript code execution in the browser if a victim uploads a malicious PDF document containing embedded JavaScript code that abuses app.alert (in the Acrobat JavaScript API).

EPSS

Процентиль: 64%
0.00471
Низкий

Дефекты

CWE-79