CVE-2025-66520 Overview
CVE-2025-66520 is a stored cross-site scripting (XSS) vulnerability in the Portfolio feature of Foxit PDF Editor Cloud (pdfonline.foxit.com). The application fails to sanitize or validate user-supplied Scalable Vector Graphics (SVG) files before inserting their contents into the HTML document structure. An authenticated attacker can upload a crafted SVG file containing embedded HTML or JavaScript. The malicious script executes in the browser of any user who renders the Portfolio file list. The flaw is classified as [CWE-79] Improper Neutralization of Input During Web Page Generation.
Critical Impact
Attackers can execute arbitrary JavaScript in victim browsers within the Foxit PDF Editor Cloud origin, enabling session data theft, action hijacking, and cross-tenant content manipulation.
Affected Products
- Foxit PDF Editor Cloud (pdfonline.foxit.com)
- Portfolio feature file rendering component
- SVG file upload and preview functionality
Discovery Timeline
- 2025-12-19 - CVE-2025-66520 published to the National Vulnerability Database
- 2026-06-17 - Last updated in NVD database
Technical Details for CVE-2025-66520
Vulnerability Analysis
The vulnerability resides in how Foxit PDF Editor Cloud handles SVG files uploaded to a Portfolio. SVG is an XML-based image format that natively supports embedded <script> tags and inline event handlers such as onload and onclick. When the Portfolio view renders the file list, the application inserts SVG content into the HTML Document Object Model (DOM) without stripping active content or enforcing a safe MIME context. Any script contained within the SVG executes with the privileges of the viewing user in the pdfonline.foxit.com origin.
Because the payload persists server-side, every user who opens the affected Portfolio triggers execution. The scope change indicated by the CVSS vector reflects that script running in the browser origin can affect resources beyond the vulnerable component alone.
Root Cause
The root cause is missing input sanitization and improper content handling on file upload and render paths. The application trusts SVG content and embeds it directly into the HTML structure rather than serving it as an isolated image resource or stripping dangerous elements. There is no Content Security Policy (CSP) restrictive enough to block inline script execution originating from user-uploaded assets.
Attack Vector
Exploitation requires an authenticated user with permission to upload files to a Portfolio and requires a victim to view that Portfolio. The attacker crafts an SVG file containing a <script> element or an SVG event handler such as onload that references arbitrary JavaScript. After upload, the payload triggers automatically whenever the Portfolio file list renders in another user's browser session. Refer to the Foxit Security Bulletins for vendor technical details.
Detection Methods for CVE-2025-66520
Indicators of Compromise
- SVG files uploaded to Portfolio storage containing <script> tags, javascript: URIs, or on* event handler attributes
- Outbound browser requests from pdfonline.foxit.com sessions to attacker-controlled domains shortly after Portfolio access
- Unexpected session token or cookie transmission originating from users who viewed shared Portfolios
Detection Strategies
- Inspect stored SVG assets for XML nodes such as <script>, <foreignObject>, and event-handler attributes prior to rendering
- Correlate file upload events with subsequent anomalous JavaScript execution and outbound requests from user browsers
- Monitor web proxy and browser telemetry for cross-origin requests initiated from the Foxit PDF Editor Cloud domain
Monitoring Recommendations
- Enable Content Security Policy violation reporting to surface inline script execution attempts within the application
- Log and review all SVG uploads to collaborative Portfolios, flagging files that contain executable XML constructs
- Alert on authentication anomalies for accounts that recently accessed Portfolios shared by external or newly created users
How to Mitigate CVE-2025-66520
Immediate Actions Required
- Restrict or disable SVG uploads to the Portfolio feature until the vendor confirms remediation
- Review recently uploaded SVG files across shared Portfolios and remove any containing active XML content
- Revoke and rotate session tokens for users who accessed Portfolios containing untrusted SVG assets
Patch Information
Foxit tracks fixes for this vulnerability through its security advisory portal. Review the Foxit Security Bulletins for the specific service update addressing CVE-2025-66520 and apply the referenced remediation to the cloud tenant configuration.
Workarounds
- Block SVG file types at the upload boundary using tenant-level file policy controls where available
- Serve user-supplied images from a sandboxed origin with a strict Content Security Policy that disables inline scripts
- Limit Portfolio sharing to trusted users and disable public link sharing for Portfolios containing mixed file types
Disclaimer: This content was generated using AI. While we strive for accuracy, please verify critical information with official sources.
