CVE-2025-66521: Foxit pdfonline.foxit.com Stored Cross-Site Scripting in Trusted Certificates Feature
A stored cross-site scripting (XSS) vulnerability exists in pdfonline.foxit.com within the Trusted Certificates feature. A crafted payload can be injected as the certificate name, which is later rendered into the DOM without proper sanitization. As a result, the injected script executes each time the Trusted Certificates view is loaded.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-66521?
CVE-2025-66521 is classified as a high severity stored cross-site scripting (XSS) vulnerability.
How do I fix CVE-2025-66521?
To fix CVE-2025-66521, ensure that proper input validation and sanitization are implemented for user input in the Trusted Certificates feature.
What software is affected by CVE-2025-66521?
CVE-2025-66521 affects the Foxit pdfonline.foxit.com application.
What are the potential consequences of CVE-2025-66521?
The potential consequences of CVE-2025-66521 include unauthorized script execution in the user's browser, leading to data theft or session hijacking.
How can I mitigate the risk of CVE-2025-66521?
To mitigate the risk of CVE-2025-66521, avoid using the affected feature until a patch or update is applied that addresses the vulnerability.