CVE-2025-66523: Reflected Cross-Site Scripting (XSS) Vulnerability in na1.foxitesign.foxit.com via Unsanitized URL Parameters
URL parameters are directly embedded into JavaScript code or HTML attributes without proper encoding or sanitization. This allows attackers to inject arbitrary scripts when an authenticated user visits a crafted link.
This issue affects na1.foxitesign.foxit.com: before 2026‑01‑16.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-66523?
CVE-2025-66523 is classified as a high-severity reflected cross-site scripting vulnerability.
How do I fix CVE-2025-66523?
To fix CVE-2025-66523, ensure proper encoding and sanitization of URL parameters before embedding them into JavaScript code or HTML attributes.
Who is affected by CVE-2025-66523?
CVE-2025-66523 affects users of Foxit service na1.foxitesign.foxit.com, specifically versions prior to January 16, 2026.
What causes CVE-2025-66523?
CVE-2025-66523 is caused by unsanitized URL parameters being directly incorporated into web pages, allowing for script injection.
Are there any known exploits for CVE-2025-66523?
As of now, while CVE-2025-66523 is known to exist, there may not be any documented public exploits.