First published: Wed Aug 11 2021(Updated: )
An issue was discovered in Foxit Reader and PhantomPDF before 10.1.4. It allows SQL Injection via crafted data at the end of a string.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Foxitsoftware Foxit Reader | <10.1.4 | |
Foxitsoftware Phantompdf | <10.1.4 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The vulnerability ID for this issue in Foxit Reader and PhantomPDF is CVE-2021-38574.
The severity of CVE-2021-38574 is critical, with a score of 9.8.
CVE-2021-38574 allows SQL Injection via crafted data at the end of a string in Foxit Reader and PhantomPDF before 10.1.4.
The affected software for CVE-2021-38574 is Foxit Reader and PhantomPDF before 10.1.4.
To fix CVE-2021-38574, update Foxit Reader and PhantomPDF to version 10.1.4 or later.