#VU21868 Cross-site scripting in Adobe Reader and Adobe Acrobat - CVE-2019-8160
Published: October 16, 2019
Adobe Reader
Adobe Acrobat
Adobe
Description
The disclosed vulnerability allows a remote attacker to perform cross-site scripting (XSS) attacks.
The vulnerability exists due to insufficient sanitization of user-supplied data passed within the PDF file. A remote attacker can trick the victim to open a specially crafted PDF file and execute arbitrary script code within the application.
Successful exploitation of this vulnerability may allow a remote attacker to steal potentially sensitive information.