cbcvebase.
CVE-2021-38574
published 2021-08-11

CVE-2021-38574: An issue was discovered in Foxit Reader and PhantomPDF before 10.1.4. It allows SQL Injection via crafted data at the end of a string.

critical9.8CVSS 3.1
AVNACLPRNUINSUCHIHAH
An issue was discovered in Foxit Reader and PhantomPDF before 10.1.4. It allows SQL Injection via crafted data at the end of a string.

Affected

2 ranges
VendorProductVersion rangeFixed in
foxitsoftwarefoxit_reader< 10.1.410.1.4
foxitsoftwarephantompdf< 10.1.410.1.4
CVE-2021-38574 — SQL Injection in Foxit Reader | cvebase