ZeroHour

CVE-2021-38572

CVSS 3.1
9.8 critical
EPSS
1%p64
Published
()
Modified
Description

An issue was discovered in Foxit Reader and PhantomPDF before 10.1.4. It allows writing to arbitrary files because the extractPages pathname is not validated.

Vendors
foxitsoftware
Products
foxit reader, phantompdf
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

In the news

No ingested article mentions this CVE yet.