CVE-2021-45979OS Command Injection in PDF Editor

Severity
7.8HIGHNVD
EPSS
2.3%
top 15.14%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedJan 4
Latest updateJan 5

Description

Foxit PDF Reader and PDF Editor before 11.1 on macOS allow remote attackers to execute arbitrary code via app.launchURL in the JavaScript API.

CVSS vector

CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:HExploitability: 1.8 | Impact: 5.9

Affected Packages2 packages

NVDfoxit/pdf_editor< 11.1
NVDfoxit/pdf_reader< 11.1

🔴Vulnerability Details

2
GHSA
GHSA-63rf-v26v-m497: Foxit PDF Reader and PDF Editor before 112022-01-05
CVEList
CVE-2021-45979: Foxit PDF Reader and PDF Editor before 112022-01-04
CVE-2021-45979 — OS Command Injection in PDF Editor | cvebase