CVE-2024-25858

HIGH

Foxit PDF Reader and PDF Editor < 2024.1 - Remote Code Execution via JavaScript Command Prompt

Title source: llm
STIX 2.1

Description

In Foxit PDF Reader before 2024.1 and PDF Editor before 2024.1, code execution via JavaScript could occur because of an unoptimized prompt message for users to review parameters of commands.

References (1)

Core 1

Scores

CVSS v3 8.4
EPSS 0.0007
EPSS Percentile 21.2%
Attack Vector LOCAL
CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact total

Details

CWE
CWE-450
Status published
Products (2)
foxit/pdf_editor < 2024.4
foxit/pdf_reader < 2024.4
Published Mar 05, 2024
Tracked Since Feb 18, 2026