CVE 6.3 MEDIUM

Foxit pdfonline.foxit.com Stored Cross-Site Scripting in Digital IDs Common Name Field_CVE-2025-66522

6.3 / 10
MEDIUM
CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:H/I:L/A:N

Description

A stored cross-site scripting (XSS) vulnerability exists in the Digital IDs functionality of the Foxit PDF Editor Cloud (pdfonline.foxit.com). The application does not properly sanitize or encode the Common Name field of Digital IDs before inserting user-supplied content into the DOM. As a result, embedded HTML or JavaScript may execute whenever the Digital IDs dialog is accessed or when the affected PDF is loaded.

Basic Information

ID CVE-2025-66522
Source Foxit
Published Dec 19, 2025 at 07:34

Affected Product

Vendor Foxit Software Inc.
Product pdfonline.foxit.com
Version before 2025‑12‑01
Affected Versions Foxit Software Inc. pdfonline.foxit.com before 2025‑12‑01

CWE Classification

References

💭 Join the Security Discussion

🔒 Your email address will not be published. Required fields are marked *

⚠️ Please be respectful and constructive in your comments. Security discussions should remain professional.