Vulnerability Description
Foxit PDF SDK For Web through 7.5.0 allows XSS. There is arbitrary JavaScript code execution in the browser if a victim uploads a malicious PDF document containing embedded JavaScript code that abuses app.alert (in the Acrobat JavaScript API).
CVSS Score
MEDIUM
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Foxit | Phantompdf | <= 9.7.5.29616 |
| Foxit | Reader | <= 10.1.3.37598 |
Related Weaknesses (CWE)
References
- https://www.foxitsoftware.com/support/security-bulletins.htmlPatchVendor Advisory
- https://www.foxitsoftware.com/support/security-bulletins.htmlPatchVendor Advisory
FAQ
What is CVE-2021-27517?
CVE-2021-27517 is a vulnerability with a CVSS score of 6.1 (MEDIUM). Foxit PDF SDK For Web through 7.5.0 allows XSS. There is arbitrary JavaScript code execution in the browser if a victim uploads a malicious PDF document containing embedded JavaScript code that abuses...
How severe is CVE-2021-27517?
CVE-2021-27517 has been rated MEDIUM with a CVSS base score of 6.1/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2021-27517?
Check the references section above for vendor advisories and patch information. Affected products include: Foxit Phantompdf, Foxit Reader.