Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2025-66522

Опубликовано: 19 дек. 2025
Источник: nvd
CVSS3: 6.3
CVSS3: 5.4
EPSS Низкий

Описание

A stored cross-site scripting (XSS) vulnerability exists in the Digital IDs functionality of the Foxit PDF Editor Cloud (pdfonline.foxit.com). The application does not properly sanitize or encode the Common Name field of Digital IDs before inserting user-supplied content into the DOM. As a result, embedded HTML or JavaScript may execute whenever the Digital IDs dialog is accessed or when the affected PDF is loaded.

Уязвимые конфигурации

Конфигурация 1
cpe:2.3:a:foxit:pdf_editor_cloud:*:*:*:*:*:*:*:*
Версия до 2025-12-01 (включая)

EPSS

Процентиль: 9%
0.00032
Низкий

6.3 Medium

CVSS3

5.4 Medium

CVSS3

Дефекты

CWE-79

Связанные уязвимости

CVSS3: 6.3
github
около 2 месяцев назад

A stored cross-site scripting (XSS) vulnerability exists in the Digital IDs functionality of the Foxit PDF Editor Cloud (pdfonline.foxit.com). The application does not properly sanitize or encode the Common Name field of Digital IDs before inserting user-supplied content into the DOM. As a result, embedded HTML or JavaScript may execute whenever the Digital IDs dialog is accessed or when the affected PDF is loaded.

EPSS

Процентиль: 9%
0.00032
Низкий

6.3 Medium

CVSS3

5.4 Medium

CVSS3

Дефекты

CWE-79