Skip to main content
Vulnerability Database/CVE-2025-66501

CVE-2025-66501: Foxit PDF Editor Cloud XSS Vulnerability

CVE-2025-66501 is a stored XSS flaw in Foxit PDF Editor Cloud that allows attackers to inject malicious scripts through the Identity First Name field. This post explains its technical details, affected versions, impact, and mitigation steps.

Published:

CVE-2025-66501 Overview

CVE-2025-66501 is a stored cross-site scripting (XSS) vulnerability affecting Foxit PDF Editor Cloud at pdfonline.foxit.com. The flaw resides in the Predefined Text feature of the Foxit eSign section. An authenticated attacker can store a crafted payload in the Identity First Name field, which is later rendered into the Document Object Model (DOM) without proper sanitization. The injected script executes when predefined text is used or when a user views document properties. The issue is tracked under CWE-79 (Improper Neutralization of Input During Web Page Generation).

Critical Impact

Attackers can execute arbitrary JavaScript in the browser context of other Foxit eSign users, enabling session theft, credential harvesting, and unauthorized actions on stored documents.

Affected Products

  • Foxit PDF Editor Cloud (pdfonline.foxit.com)
  • Foxit eSign section — Predefined Text feature
  • Identity profile First Name input field

Discovery Timeline

  • 2025-12-19 - CVE-2025-66501 published to NVD
  • 2026-06-17 - Last updated in NVD database

Technical Details for CVE-2025-66501

Vulnerability Analysis

The vulnerability is a stored XSS flaw in the cloud-hosted Foxit PDF Editor. The application accepts user-supplied content in the Identity First Name field without applying output encoding or input sanitization when the value is later inserted into the DOM. Because the injected value persists in the user's identity profile, the payload triggers each time the Predefined Text feature is invoked or a recipient views document properties containing that identity data.

Exploitation requires an authenticated attacker to place the payload and a second user to trigger the affected view. The scope change reflects the ability of the injected script to run in a browser context beyond the attacker's own session, affecting other Foxit eSign users who process documents containing the crafted identity data.

Root Cause

The root cause is missing neutralization of HTML and JavaScript control characters in the First Name field. The application stores raw input and reflects it into the DOM as markup rather than as text content. This allows <script> tags and event-handler attributes to be interpreted by the browser when the field is rendered inside predefined text templates or document metadata views.

Attack Vector

The attack requires network access to pdfonline.foxit.com, low-privileged authentication to the Foxit eSign service, and user interaction on the victim side. An attacker modifies the First Name value in their identity profile to include a JavaScript payload. The payload is stored server-side. When a legitimate user opens a document that renders the predefined text or views document properties referencing the attacker's identity, the browser executes the injected script under the origin of pdfonline.foxit.com.

No verified public proof-of-concept code is available. See the Foxit Security Bulletin for vendor-supplied details.

Detection Methods for CVE-2025-66501

Indicators of Compromise

  • Identity profile fields (specifically First Name) containing HTML tags, <script> markers, or JavaScript event handlers such as onerror= or onload=.
  • Unexpected outbound requests from user browsers to attacker-controlled domains shortly after opening Foxit eSign documents or viewing document properties.
  • Anomalous session activity on pdfonline.foxit.com accounts, such as unauthorized document access or profile modifications following eSign workflows.

Detection Strategies

  • Review Foxit eSign audit logs for identity profile edits that introduce non-alphabetic characters into name fields.
  • Deploy Content Security Policy (CSP) reporting to capture inline script violations originating from Foxit eSign pages.
  • Inspect browser telemetry for script execution or DOM mutations tied to the pdfonline.foxit.com origin during document rendering.

Monitoring Recommendations

  • Monitor web proxy and DNS logs for connections initiated from browser sessions active on pdfonline.foxit.com.
  • Alert on any user identity field values that fail server-side or client-side validation for alphanumeric content.
  • Track document property views and predefined text usage across tenants to correlate mass exposure to a single malicious identity record.

How to Mitigate CVE-2025-66501

Immediate Actions Required

  • Audit all Foxit eSign identity profiles within your tenant and remove entries containing HTML or JavaScript payloads in name fields.
  • Rotate session tokens and passwords for any user account whose profile shows suspicious modification.
  • Restrict eSign document sharing with untrusted external identities until the vendor patch is confirmed applied.

Patch Information

Foxit hosts the affected product as a cloud service; remediation is applied server-side by the vendor. Consult the Foxit Security Bulletin to confirm the fixed version and effective date for pdfonline.foxit.com.

Workarounds

  • Avoid using the Predefined Text feature with identities sourced from unverified users.
  • Instruct users to refrain from opening document properties on eSign documents from unknown senders until the vendor confirms remediation.
  • Enforce browser-level script controls or extension-based XSS filtering for users who must access pdfonline.foxit.com during the exposure window.
bash
# Example CSP header enforcement at an upstream proxy or browser policy
# to constrain inline script execution on the Foxit eSign origin
Content-Security-Policy: default-src 'self'; script-src 'self'; object-src 'none'; base-uri 'self'; report-uri /csp-report

Disclaimer: This content was generated using AI. While we strive for accuracy, please verify critical information with official sources.

Default Legacy - Prefooter | Experience the World’s Most Advanced Cybersecurity Platform

Experience the Most Advanced Cybersecurity Platform

See how the world’s most intelligent, autonomous cybersecurity platform can protect your organization today and into the future.