CVE-2021-27517

Severity
6.1MEDIUM
EPSS
0.5%
top 35.39%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedJul 20
Latest updateMay 24

Description

Foxit PDF SDK For Web through 7.5.0 allows XSS. There is arbitrary JavaScript code execution in the browser if a victim uploads a malicious PDF document containing embedded JavaScript code that abuses app.alert (in the Acrobat JavaScript API).

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:NExploitability: 2.8 | Impact: 2.7

Affected Packages2 packages

NVDfoxit/reader10.1.3.37598
NVDfoxit/phantompdf10.0.0.010.1.3.37598+1

Patches

🔴Vulnerability Details

2
GHSA
GHSA-gh4f-wqp7-vmm2: Foxit PDF SDK For Web through 72022-05-24
CVEList
CVE-2021-27517: Foxit PDF SDK For Web through 72021-07-20
CVE-2021-27517 (MEDIUM CVSS 6.1) | Foxit PDF SDK For Web through 7.5.0 | cvebase.io