JavaScript Injection Vulnerability in Foxit PDF Software
CVE-2025-66523

6.1MEDIUM

Key Information:

Vendor

Foxit Inc.

Vendor
CVE Published:
20 January 2026

What is CVE-2025-66523?

This vulnerability allows attackers to inject arbitrary scripts by manipulating URL parameters that are embedded directly into JavaScript code or HTML attributes without proper encoding or sanitization. When an authenticated user clicks on a specially crafted link, this flaw can lead to the execution of malicious scripts in the user's browser, potentially compromising sensitive data and application integrity.

Affected Version(s)

na1.foxitesign.foxit.com before 2026‑01‑16

References

CVSS V3.1

Score:
6.1
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Novee
.