CVE-2018-21242: Infoleak
Published Jun 4, 2020
·Updated
An issue was discovered in Foxit PhantomPDF before 8.3.6. It allows Remote Code Execution via a GoToE or GoToR action.
Affected Software
1 affected component
Foxitsoftware Phantompdf<8.3.6
Event History
Jun 4, 2020
CVE Published
via MITRE·04:23 PM
Data Sourced
via MITRE·04:23 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2018-21242?
CVE-2018-21242 has a high severity rating due to its potential for Remote Code Execution.
2
How do I fix CVE-2018-21242?
To fix CVE-2018-21242, update Foxit PhantomPDF to version 8.3.6 or later.
3
What types of actions can trigger CVE-2018-21242?
CVE-2018-21242 can be triggered by GoToE or GoToR actions in affected versions of Foxit PhantomPDF.
4
Which versions of Foxit PhantomPDF are affected by CVE-2018-21242?
Foxit PhantomPDF versions prior to 8.3.6 are affected by CVE-2018-21242.
5
What can happen if CVE-2018-21242 is exploited?
If exploited, CVE-2018-21242 can allow an attacker to execute remote code on the vulnerable system.