CVE-2025-66502: Foxit pdfonline.foxit.com Stored Cross-Site Scripting in Page Templates Feature
A stored cross-site scripting (XSS) vulnerability exists in pdfonline.foxit.com within the Page Templates feature. A crafted payload can be stored as the template name, which is later rendered into the DOM without proper sanitization. As a result, the injected script executes each time the affected PDF is loaded.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-66502?
CVE-2025-66502 has a high severity due to its potential for allowing stored cross-site scripting attacks.
How do I fix CVE-2025-66502?
To fix CVE-2025-66502, ensure that proper input validation and output encoding are implemented to sanitize template names stored in the application.
What type of vulnerability is CVE-2025-66502?
CVE-2025-66502 is a stored cross-site scripting (XSS) vulnerability.
What component is affected by CVE-2025-66502?
The Page Templates feature in the pdfonline.foxit.com application is affected by CVE-2025-66502.
Can CVE-2025-66502 be exploited remotely?
Yes, CVE-2025-66502 can be exploited remotely by injecting scripts that execute in the context of users accessing the compromised templates.