GHSA-mw87-v3r3-7j2hMediumCVSS 4.7

When implementing the JavaScript interface, Foxit PDF Editor/Reader did not perform the attribute...

Published
September 23, 2026
Last Modified
September 23, 2026

🔗 CVE IDs covered (1)

📋 Description

When implementing the JavaScript interface, Foxit PDF Editor/Reader did not perform the attribute authorization checks required by the specification. As a result, a trusted malicious PDF could potentially access sensitive content from other documents within the same process and transmit it externally.

🔗 References (3)