vendor:
Foxit Reader
by:
Nassim Asrir
7.8
CVSS
HIGH
Remote Command Execution
78
CWE
Product Name: Foxit Reader
Affected Version From: 9.7.2001
Affected Version To: 9.7.2001
Patch Exists: NO
Related CWE: CVE-2020-14425
CPE: a:foxitsoftware:foxit_reader:9.7.1
Platforms Tested: Windows
2020
Foxit Reader 9.7.1 – Remote Command Execution (Javascript API)
Foxit Reader before 10.0 allows Remote Command Execution via the unsafe app.opencPDFWebPage JavaScript API which allows an attacker to execute local files on the file system and bypass the security dialog.
Mitigation:
Update to Foxit Reader 10.0 or later version