CVE-2025-66500: Foxit webplugins.foxit.com Stored Cross-Site Scripting via postMessage Vulnerability
A stored cross-site scripting (XSS) vulnerability exists in webplugins.foxit.com. A postMessage handler fails to validate the message origin and directly assigns externalPath to a script source, allowing an attacker to execute arbitrary JavaScript when a crafted postMessage is received.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-66500?
CVE-2025-66500 is considered a high severity vulnerability due to its potential for arbitrary JavaScript execution.
How do I fix CVE-2025-66500?
To fix CVE-2025-66500, ensure that the webplugin is updated to the latest version provided by Foxit that addresses the XSS vulnerability.
What type of vulnerability is CVE-2025-66500?
CVE-2025-66500 is a stored cross-site scripting (XSS) vulnerability.
What can an attacker do with CVE-2025-66500?
An attacker can execute arbitrary JavaScript in the context of a victim's session through a crafted postMessage.
Where is CVE-2025-66500 located?
CVE-2025-66500 exists in webplugins.foxit.com, specifically within the postMessage handler.