CVE-2025-66522

Source
https://cve.org/CVERecord?id=CVE-2025-66522
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2025-66522.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2025-66522
Published
2025-12-19T08:15:54.407Z
Modified
2026-03-13T03:41:42.345197Z
Severity
  • 5.4 (Medium) CVSS_V3 - CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N CVSS Calculator
Summary
[none]
Details

A stored cross-site scripting (XSS) vulnerability exists in the Digital IDs functionality of the Foxit PDF Editor Cloud (pdfonline.foxit.com). The application does not properly sanitize or encode the Common Name field of Digital IDs before inserting user-supplied content into the DOM. As a result, embedded HTML or JavaScript may execute whenever the Digital IDs dialog is accessed or when the affected PDF is loaded.

References

Affected packages

Git /

Affected ranges

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2025-66522.json"
unresolved_ranges
[
    {
        "events": [
            {
                "introduced": "0"
            },
            {
                "last_affected": "2025-12-01"
            }
        ]
    }
]