Skip to main content
Vulnerability Database/CVE-2025-66519

CVE-2025-66519: Foxit PDF Editor Cloud XSS Vulnerability

CVE-2025-66519 is a stored XSS vulnerability in Foxit PDF Editor Cloud that allows attackers to inject malicious scripts through the Layer Import functionality. This post explains its impact, affected versions, and mitigation steps.

Published:

CVE-2025-66519 Overview

CVE-2025-66519 is a stored cross-site scripting (XSS) vulnerability in Foxit PDF Editor Cloud at pdfonline.foxit.com. The flaw resides in the Layer Import functionality. An attacker can inject a crafted payload into the Create new Layer field during layer import. The application later renders that value into the Document Object Model (DOM) without proper sanitization. When another user opens the Layers panel, the injected script executes in their browser session.

The issue is classified under CWE-79: Improper Neutralization of Input During Web Page Generation. Exploitation requires an authenticated user with low privileges and interaction from a victim who opens the Layers panel.

Critical Impact

Attackers can execute arbitrary JavaScript in the browser context of any user who opens the crafted PDF's Layers panel, enabling session token theft, cross-tenant actions in the cloud editor, and phishing pivots.

Affected Products

  • Foxit PDF Editor Cloud (pdfonline.foxit.com) — Layer Import functionality
  • Foxit pdf_editor_cloud (all versions prior to vendor remediation)
  • Documents processed through the cloud editor's Layers panel

Discovery Timeline

  • 2025-12-19 - CVE-2025-66519 published to the National Vulnerability Database (NVD)
  • 2026-06-17 - Last updated in NVD database

Technical Details for CVE-2025-66519

Vulnerability Analysis

The vulnerability sits in the layer-import workflow of Foxit's browser-based PDF editor. When a user imports a layer, the client accepts a name from the Create new Layer input. That value is persisted with the document and later injected into the Layers panel markup. The rendering path does not encode HTML control characters or strip active content before insertion into the DOM.

Because the payload is stored server-side with the document, this is a persistent XSS rather than a reflected one. Any user who opens the affected document and expands the Layers panel triggers execution. The scope metric indicates the impact crosses a trust boundary. A payload authored by a low-privilege collaborator can therefore execute in the context of a document owner or another tenant user viewing the shared file.

Root Cause

The root cause is missing output encoding on user-controlled layer metadata. The Create new Layer field accepts arbitrary strings, including HTML tags and JavaScript event handlers. The Layers panel renderer treats the stored string as trusted markup and inserts it directly into the DOM through an unsafe sink such as innerHTML. Neither server-side input validation nor client-side contextual escaping neutralizes the payload before rendering.

Attack Vector

An authenticated attacker creates or edits a PDF in Foxit PDF Editor Cloud and initiates a layer import. In the Create new Layer name field, the attacker supplies a payload containing an HTML element with a JavaScript event handler, for example an <img> tag with an onerror attribute or a <svg> tag with an inline handler. The attacker saves the document and shares it with a target or waits for a collaborator to open it.

When the victim opens the Layers panel, the browser parses the injected markup and executes the script under the origin pdfonline.foxit.com. The script can read session cookies scoped to the origin, exfiltrate document contents accessible to the victim, perform actions on behalf of the victim through the editor's authenticated APIs, or redirect the victim to attacker-controlled infrastructure. No verified proof-of-concept code has been published for this issue.

Detection Methods for CVE-2025-66519

Indicators of Compromise

  • Stored PDF documents whose layer metadata contains HTML tags, JavaScript URIs, or event-handler attributes such as onerror, onload, or onclick.
  • Outbound browser requests from pdfonline.foxit.com sessions to unfamiliar third-party domains immediately after users open a shared document.
  • Anomalous session-cookie usage from IP addresses that do not match the legitimate user's typical geolocation.

Detection Strategies

  • Inspect stored PDF layer names and metadata for HTML control characters (<, >, ", ') and JavaScript sinks before rendering.
  • Enable Content Security Policy (CSP) reporting on the cloud editor origin and monitor script-src and inline-event-handler violation reports.
  • Correlate document-open events with subsequent DOM-based network activity to identify script execution triggered by the Layers panel.

Monitoring Recommendations

  • Log every layer-import action with the raw layer-name value and the acting user identity for forensic review.
  • Alert on session-token use from new user-agent or IP combinations shortly after a shared document is opened.
  • Track help-desk reports of unexpected redirects, credential prompts, or errors when users interact with the Layers panel.

How to Mitigate CVE-2025-66519

Immediate Actions Required

  • Review the Foxit Security Bulletins and apply the vendor's fix for Foxit PDF Editor Cloud as soon as it is published for your tenant.
  • Audit recently imported or shared PDFs for suspicious layer names containing HTML or script fragments and quarantine offending documents.
  • Rotate authentication tokens and session cookies for users who opened untrusted shared documents in the affected window.

Patch Information

Foxit tracks fixes for pdf_editor_cloud through its central advisory portal. Refer to the Foxit Security Bulletins page for the specific build or service-side remediation addressing CVE-2025-66519. Because Foxit PDF Editor Cloud is a hosted service, remediation is delivered server-side by the vendor and does not require a client update. Confirm remediation by re-testing the Layer Import field against a benign HTML payload in a controlled account.

Workarounds

  • Restrict Foxit PDF Editor Cloud sharing to trusted internal users until the vendor confirms the fix is deployed to your tenant.
  • Instruct users to avoid opening the Layers panel on documents received from external or untrusted sources.
  • Enforce a strict Content Security Policy at the browser or enterprise-proxy layer to block inline script execution on pdfonline.foxit.com.
  • Use browser isolation or a dedicated browser profile for handling untrusted PDF collaborations to contain any script execution.
bash
# Configuration example
# Example enterprise CSP override for pdfonline.foxit.com via a forward proxy
# Blocks inline handlers and constrains script sources.
Content-Security-Policy: default-src 'self' https://pdfonline.foxit.com; \
  script-src 'self' https://pdfonline.foxit.com; \
  object-src 'none'; base-uri 'none'; frame-ancestors 'self'

Disclaimer: This content was generated using AI. While we strive for accuracy, please verify critical information with official sources.

Default Legacy - Prefooter | Experience the World’s Most Advanced Cybersecurity Platform

Experience the Most Advanced Cybersecurity Platform

See how the world’s most intelligent, autonomous cybersecurity platform can protect your organization today and into the future.