First published: Thu Jun 04 2020(Updated: )
An issue was discovered in Foxit PhantomPDF before 8.3.6. It allows Remote Code Execution via a GoToE or GoToR action.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Foxit PhantomPDF | <8.3.6 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2018-21242 has a high severity rating due to its potential for Remote Code Execution.
To fix CVE-2018-21242, update Foxit PhantomPDF to version 8.3.6 or later.
CVE-2018-21242 can be triggered by GoToE or GoToR actions in affected versions of Foxit PhantomPDF.
Foxit PhantomPDF versions prior to 8.3.6 are affected by CVE-2018-21242.
If exploited, CVE-2018-21242 can allow an attacker to execute remote code on the vulnerable system.