CVE-2025-66519: Foxit pdfonline.foxit.com Stored Cross-Site Scripting in Layer Import Functionality
A stored cross-site scripting (XSS) vulnerability exists in pdfonline.foxit.com within the Layer Import functionality. A crafted payload can be injected into the “Create new Layer” field during layer import and is later rendered into the DOM without proper sanitization. As a result, the injected script executes when the Layers panel is accessed.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-66519?
CVE-2025-66519 is classified as a medium severity stored cross-site scripting (XSS) vulnerability.
How do I fix CVE-2025-66519?
To fix CVE-2025-66519, ensure that proper input validation and output sanitization are implemented in the Layer Import functionality.
What is the impact of CVE-2025-66519?
The impact of CVE-2025-66519 allows an attacker to inject malicious scripts that can be executed in the context of another user's session.
Is CVE-2025-66519 specific to certain versions of Foxit pdfonline?
Yes, CVE-2025-66519 affects Foxit pdfonline but specific version details are not disclosed.
How can users protect themselves from CVE-2025-66519?
Users can protect themselves from CVE-2025-66519 by avoiding untrusted inputs and being cautious with content created via the Layer Import functionality.