Impact
The flaw lies in the PDF creation feature of Foxit PDF Services API, which permits referencing external files. Although local file access is limited, an attacker can exploit the API by sending a request whose URL redirects to another host. The redirection bypasses the API’s validation and triggers a blind Server‑Side Request Forgery (SSRF). This allows the attacker to cause the service to reach any network endpoint, potentially leaking data that the service can access.
Affected Systems
Foxit Software Inc.’s Foxit PDF API is impacted. No specific product versions are listed in the advisory, so any deployment using the attackable feature should be considered vulnerable until a patch is confirmed.
Risk and Exploitability
The vulnerability carries a CVSS score of 8.5, indicating high severity. The EPSS score is not provided, but the lack of a CISA KEV listing does not diminish the likelihood of exploitation in environments where the API is publicly exposed. Attackers would need to craft a creation request with a redirecting URL; no local authentication is required, making the attack a remote exploitation scenario that can lead to information disclosure.
OpenCVE Enrichment