CVE-2025-66500
EUVD-2025-20446019.12.2025, 08:15
A stored cross-site scripting (XSS) vulnerability exists in webplugins.foxit.com. A postMessage handler fails to validate the message origin and directly assigns externalPath to a script source, allowing an attacker to execute arbitrary JavaScript when a crafted postMessage is received.
Affected Products (NVD)
| Vendor | Product | Version |
|---|---|---|
| foxit | pdf_editor_cloud | 𝑥 < 2025-12-01 |
𝑥
= Vulnerable software versions
Vulnerability Media Exposure