Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-rqmw-g85w-m87f

Опубликовано: 11 дек. 2025
Источник: github
Github: Не прошло ревью
CVSS3: 6.5

Описание

An issue was discovered in Foxit PDF and Editor for Windows and macOS before 13.2 and 2025 before 2025.2. A crafted PDF can use JavaScript to alter annotation content and subsequently clear the file's modification status via JavaScript interfaces. This circumvents digital signature verification by hiding document modifications, allowing an attacker to mislead users about the document's integrity and compromise the trustworthiness of signed PDFs.

An issue was discovered in Foxit PDF and Editor for Windows and macOS before 13.2 and 2025 before 2025.2. A crafted PDF can use JavaScript to alter annotation content and subsequently clear the file's modification status via JavaScript interfaces. This circumvents digital signature verification by hiding document modifications, allowing an attacker to mislead users about the document's integrity and compromise the trustworthiness of signed PDFs.

EPSS

Процентиль: 2%
0.00015
Низкий

6.5 Medium

CVSS3

Дефекты

CWE-347

Связанные уязвимости

CVSS3: 6.5
nvd
около 2 месяцев назад

An issue was discovered in Foxit PDF and Editor for Windows and macOS before 13.2 and 2025 before 2025.2. A crafted PDF can use JavaScript to alter annotation content and subsequently clear the file's modification status via JavaScript interfaces. This circumvents digital signature verification by hiding document modifications, allowing an attacker to mislead users about the document's integrity and compromise the trustworthiness of signed PDFs.

EPSS

Процентиль: 2%
0.00015
Низкий

6.5 Medium

CVSS3

Дефекты

CWE-347