Foxit pdfonline.foxit.com Stored Cross-Site Scripting in eSign Predefined Text Feature
Vulnerability Description
A stored cross-site scripting (XSS) vulnerability exists in pdfonline.foxit.com within the Predefined Text feature of the Foxit eSign section. A crafted payload can be stored via the Identity “First Name” field, which is later rendered into the DOM without proper sanitization. As a result, the injected script may execute when predefined text is used or when viewing document properties.
Impact Analysis
Refer to official advisory for detailed impact metrics.
Remediation
Ensure systems are updated to the latest vendor-supplied patch levels.
Am I Vulnerable?
Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2025-66501
Credits & Attribution
The following person or organization is credited with identifying this vulnerability, as recorded in the NVD database:
- Novee
More from Foxit Software Inc.
View All →Affected Vendor
Foxit Software Inc.
View all reports →