CVE-2021-38574: SQL Injection
Published Aug 11, 2021
·Updated
An issue was discovered in Foxit Reader and PhantomPDF before 10.1.4. It allows SQL Injection via crafted data at the end of a string.
Affected Software
2 affected components
Foxitsoftware Foxit Reader<10.1.4
Foxitsoftware Phantompdf<10.1.4
Event History
Aug 11, 2021
CVE Published
via MITRE·09:12 PM
Data Sourced
via MITRE·09:12 PM
Description
Data Sourced
via NVD·10:15 PM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the vulnerability ID for this issue in Foxit Reader and PhantomPDF?
The vulnerability ID for this issue in Foxit Reader and PhantomPDF is CVE-2021-38574.
2
What is the severity of CVE-2021-38574?
The severity of CVE-2021-38574 is critical, with a score of 9.8.
3
How does CVE-2021-38574 affect Foxit Reader and PhantomPDF?
CVE-2021-38574 allows SQL Injection via crafted data at the end of a string in Foxit Reader and PhantomPDF before 10.1.4.
4
What is the affected software for CVE-2021-38574?
The affected software for CVE-2021-38574 is Foxit Reader and PhantomPDF before 10.1.4.
5
How can I fix CVE-2021-38574?
To fix CVE-2021-38574, update Foxit Reader and PhantomPDF to version 10.1.4 or later.