CVE-2020-13804: Critical severity foxit phantompdf vulnerability
Published Jun 4, 2020
·Updated
An issue was discovered in Foxit Reader and PhantomPDF before 9.7.2. It allows information disclosure of a hardcoded username and password in the DocuSign plugin.
Affected Software
2 affected components
Foxitsoftware Phantompdf<9.7.2
Foxitsoftware Reader<9.7.2
Remediation
Patch Available
Event History
Jun 4, 2020
CVE Published
via MITRE·02:38 PM
Data Sourced
via MITRE·02:38 PM
Description
Frequently Asked Questions
1
What is the vulnerability ID?
The vulnerability ID is CVE-2020-13804.
2
What is the severity of CVE-2020-13804?
The severity of CVE-2020-13804 is critical, with a severity value of 9.8.
3
Which software products are affected by CVE-2020-13804?
Foxit Reader and PhantomPDF versions up to 9.7.2 are affected by CVE-2020-13804.
4
What is the impact of CVE-2020-13804?
CVE-2020-13804 allows information disclosure of a hardcoded username and password in the DocuSign plugin of Foxit Reader and PhantomPDF.
5
How can I fix CVE-2020-13804?
Upgrade Foxit Reader and PhantomPDF to version 9.7.2 or later to fix CVE-2020-13804.