Impact
Foxit PDF Editor and Reader treat incoming documents that are not well‑formed PDFs as valid files, allowing embedded XML external entities to reference local file paths. When such a document is parsed, the XML processor resolves the entity, reading data from any file the current user can access and returning it to the application. The vulnerability is an XML External Entity flaw (CWE‑611) that enables an attacker to read proprietary or system files within the user's permission range, representing moderate confidentiality and integrity impact as indicated by the CVSS score of 6.5, but it does not allow code execution or full system compromise.
Affected Systems
Foxit Software Inc.’s Foxit PDF Editor and Foxit PDF Reader are affected. No specific version information is provided, so all versions prior to the vendor’s fix remain vulnerable.
Risk and Exploitability
The flaw requires an attacker to supply a crafted PDF file and for a victim to open that file within the Foxit application. Because the attack is local to the user target, the vulnerability offers moderate confidentiality and integrity impact with a CVSS score of 6.5. The EPSS score of less than 1% indicates a low likelihood of exploitation in the wild, and the vulnerability is not listed in the CISA KEV catalog.
OpenCVE Enrichment