Skip to main content
Vulnerability Database/CVE-2025-66522

CVE-2025-66522: Foxit PDF Editor Cloud XSS Vulnerability

CVE-2025-66522 is a stored XSS vulnerability in Foxit PDF Editor Cloud that allows malicious scripts to execute through unsanitized Digital ID fields. This article covers technical details, security impact, and mitigation strategies.

Published:

CVE-2025-66522 Overview

CVE-2025-66522 is a stored cross-site scripting (XSS) vulnerability in the Digital IDs functionality of Foxit PDF Editor Cloud, hosted at pdfonline.foxit.com. The application fails to sanitize or encode the Common Name field of Digital IDs before inserting user-supplied content into the Document Object Model (DOM). Attackers can embed HTML or JavaScript payloads that execute whenever a victim opens the Digital IDs dialog or loads an affected PDF. The flaw is classified under [CWE-79] Improper Neutralization of Input During Web Page Generation.

Critical Impact

Attackers can execute arbitrary JavaScript in the context of a victim's Foxit PDF Editor Cloud session, enabling session data theft, unauthorized document actions, and cross-tenant content manipulation.

Affected Products

  • Foxit PDF Editor Cloud (pdfonline.foxit.com) web application
  • Digital IDs feature (Common Name input field)
  • PDF documents containing crafted Digital IDs loaded by the service

Discovery Timeline

  • 2025-12-19 - CVE-2025-66522 published to the National Vulnerability Database (NVD)
  • 2026-06-17 - Last updated in the NVD database

Technical Details for CVE-2025-66522

Vulnerability Analysis

The vulnerability resides in the client-side rendering path of the Digital IDs dialog. When Foxit PDF Editor Cloud reads a Digital ID from a PDF or user submission, the Common Name (CN) attribute is inserted into the DOM without contextual output encoding. Because the CN field is stored server-side and rendered every time the dialog is opened, the payload persists across sessions and users who share or receive the affected document. Execution occurs in the origin of pdfonline.foxit.com, giving injected script access to session cookies, in-app APIs, and any cached document state accessible to the victim.

Root Cause

The root cause is missing output encoding on user-controlled Digital ID metadata. The application treats the Common Name as trusted text and writes it into an HTML sink using an operation equivalent to innerHTML rather than a safe text-node assignment. HTML tags such as <img onerror=...> or <svg> handlers are parsed and executed instead of being displayed literally.

Attack Vector

An authenticated attacker creates or edits a Digital ID and supplies a Common Name value containing a JavaScript payload. The attacker then shares a PDF referencing that Digital ID, or waits for a victim to view the Digital IDs dialog. User interaction is required, and the impact crosses a scope boundary because the injected script runs in the trusted Foxit web origin. This can lead to hijacking of document workflows, exfiltration of PDF content the victim can access, and abuse of Foxit account functionality.

No public proof-of-concept exploit or exploitation activity has been reported at the time of publication.

Detection Methods for CVE-2025-66522

Indicators of Compromise

  • Digital IDs whose Common Name field contains HTML tags, angle brackets, or JavaScript event handlers such as onerror, onload, or onclick.
  • Outbound requests from browser sessions on pdfonline.foxit.com to unfamiliar domains immediately after opening a shared PDF or the Digital IDs dialog.
  • Unexpected DOM mutations or script injections logged by browser-side monitoring on the Foxit web application.

Detection Strategies

  • Inspect stored Digital ID records for Common Name values that contain <, >, script, javascript:, or on\w+= patterns.
  • Correlate PDF sharing events with anomalous browser telemetry from users who opened those documents.
  • Review web application logs for repeated Digital ID creation or update requests originating from a single account.

Monitoring Recommendations

  • Enable browser and endpoint telemetry to capture script execution and network beacons from cloud PDF sessions.
  • Alert on Content Security Policy (CSP) violation reports emitted by the Foxit web origin, if reporting is configured.
  • Track user-account activity for privilege changes or session token reuse following interaction with untrusted PDFs.

How to Mitigate CVE-2025-66522

Immediate Actions Required

  • Restrict use of Foxit PDF Editor Cloud to trusted documents until Foxit confirms remediation on pdfonline.foxit.com.
  • Audit existing Digital IDs and remove or rewrite any Common Name values containing HTML or scripting syntax.
  • Advise users to avoid opening the Digital IDs dialog on PDFs received from untrusted senders.

Patch Information

CVE-2025-66522 affects a cloud-hosted service, so remediation is delivered server-side by the vendor rather than through a customer-installable patch. Monitor the Foxit Security Bulletins page for confirmation that the Digital IDs rendering path has been fixed with proper output encoding.

Workarounds

  • Access pdfonline.foxit.com from an isolated browser profile or dedicated browser to limit session and credential exposure.
  • Use browser extensions or enterprise policies that enforce a strict Content Security Policy to block inline script execution on the Foxit web origin.
  • Route access to the Foxit cloud through a secure web gateway that can inspect and strip suspicious content from cloud application responses.
bash
# Example: block access to the affected endpoint at an enterprise proxy
# until the vendor confirms remediation
deny host pdfonline.foxit.com

Disclaimer: This content was generated using AI. While we strive for accuracy, please verify critical information with official sources.

Default Legacy - Prefooter | Experience the World’s Most Advanced Cybersecurity Platform

Experience the Most Advanced Cybersecurity Platform

See how the world’s most intelligent, autonomous cybersecurity platform can protect your organization today and into the future.