CVE-2025-66523
Last modified
CVE-2025-66523 is a medium-severity vulnerability rated 6.1/10 on the CVSS scale. URL parameters are directly embedded into JavaScript code or HTML attributes without proper encoding or sanitization. This allows attackers to inject arbitrary scripts when an authenticated user visits a crafted link. This issue affects na1.foxitesign.foxit.com: before 2026‑01‑16.. EPSS estimates a 0.16% chance of exploitation in the next 30 days.
Description
URL parameters are directly embedded into JavaScript code or HTML attributes without proper encoding or sanitization. This allows attackers to inject arbitrary scripts when an authenticated user visits a crafted link. This issue affects na1.foxitesign.foxit.com: before 2026‑01‑16.
Metrics
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Foxit | Esign | < 2026-01-16 |
References
- https://www.foxit.com/support/security-bulletins.htmlVendor Advisory
Timeline
- Published
- Last Modified
- Status
- Analyzed
Frequently Asked Questions
What is CVE-2025-66523?
How severe is CVE-2025-66523?
How do I fix CVE-2025-66523?
Are you affected by CVE-2025-66523?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
