CVE-2021-45980

Description

Foxit PDF Reader and PDF Editor before 11.1 on macOS allow remote attackers to execute arbitrary code via getURL in the JavaScript API.

Risk Information

Base Score
7.8
MODERATE
Vector
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
EPSS Score
Exploitation Probability
0.775

Associated Vulnerability

VulnerabilityOS Platform
Multiple vulnerabilities are fixed in Foxit PDF Editor 11 (ML) (EXE) (11.1.0.52543)Windows
Multiple vulnerabilities are fixed in Foxit PDF Editor 11 (ML) (MSI) (11.1.0.52543)Windows
Multiple vulnerabilities are fixed in Foxit PDF Editor 11 (EXE) (11.1.0.52543)Windows
Multiple vulnerabilities are fixed in Foxit PDF Editor 11 (MSI) (11.1.0.52543)Windows
Vulnerabilities CVE-2021-45978,CVE-2021-45979,CVE-2021-45980 are fixed in Foxit PDF Editor 11 (ML) (EXE) (11.1.0.52543)Windows
Vulnerabilities CVE-2021-45978,CVE-2021-45979,CVE-2021-45980 are fixed in Foxit PDF Editor 11 (ML) (MSI) (11.1.0.52543)Windows
Vulnerabilities CVE-2021-45978,CVE-2021-45979,CVE-2021-45980 are fixed in Foxit PDF Editor 11 (EXE) (11.1.0.52543)Windows
Vulnerabilities CVE-2021-45978,CVE-2021-45979,CVE-2021-45980 are fixed in Foxit PDF Editor 11 (MSI) (11.1.0.52543)Windows

Patch Details

Click to see the patches provided by ManageEngine for this CVE
Patch IDPatch Description
PATCH-330913Foxit PDF Editor 11 (ML) (EXE) (11.2.6.53790)
PATCH-330914Foxit PDF Editor 11 (ML) (MSI) (11.2.6.53790)
PATCH-330912Foxit PDF Editor 11 (EXE) (11.2.6.53790)
PATCH-330915Foxit PDF Editor 11 (MSI) (11.2.6.53790)
PATCH-333320Foxit PDF Editor 11 (ML) (EXE) (11.2.7.53812)
PATCH-333321Foxit PDF Editor 11 (ML) (MSI) (11.2.7.53812)
PATCH-333323Foxit PDF Editor 11 (EXE) (11.2.7.53812)
PATCH-333322Foxit PDF Editor 11 (MSI) (11.2.7.53812)

References

https://nvd.nist.gov/vuln/detail/CVE-2023-1234
https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-1234