CVE-2021-27517

MEDIUM

Foxit PhantomPDF < 9.7.5.29616 and Reader < 10.1.3.37598 - Stored Cross-Site Scripting via Embedded JavaScript in PDF

Title source: llm
STIX 2.1

Description

Foxit PDF SDK For Web through 7.5.0 allows XSS. There is arbitrary JavaScript code execution in the browser if a victim uploads a malicious PDF document containing embedded JavaScript code that abuses app.alert (in the Acrobat JavaScript API).

References (1)

Core 1
Core References
Patch, Vendor Advisory x_refsource_misc
https://www.foxitsoftware.com/support/security-bulletins.html

Scores

CVSS v3 6.1
EPSS 0.0047
EPSS Percentile 64.8%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N

Details

CWE
CWE-79
Status published
Products (2)
foxit/phantompdf < 9.7.5.29616
foxit/reader < 10.1.3.37598
Published Jul 20, 2021
Tracked Since Feb 18, 2026