#VU101824 Information disclosure in Foxit PDF Reader for Windows and Foxit PDF Editor (formerly Foxit PhantomPDF)
Published: December 18, 2024 / Updated: December 18, 2024
Foxit PDF Reader for Windows
Foxit PDF Editor (formerly Foxit PhantomPDF)
Foxit Software Inc.
Description
The vulnerability allows a remote attacker to gain access to potentially sensitive information.
The vulnerability exists due to the application fails to provide a reasonable prompt for user
confirmation when executing the “app.openDoc”/“LaunchAction” functions,
or ignores the encryption elements and transmits form content in clear
text without a proper prompt for users. A remote attacker can trick the victim into opening a specially crafted XFA file and gain access to sensitive information.