CVE-2019-6754 is a high-severity vulnerability affecting Foxit Reader and PhantomPDF versions 9.3.10826 and earlier, allowing remote attackers to execute arbitrary code. The flaw stems from improper validation of user-supplied paths in the localFileStorage method, leading to code execution in the context of the current process. Exploitation requires user interaction, such as opening a malicious file or visiting a malicious page. While the CVSS score is 7.8 (High), there is no evidence of active exploitation, publicly available exploit code, or significant community discussion surrounding this vulnerability.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
<= 9.4.1.16828CPE matchmatch criteria | cpe:2.3:a:foxitsoftware:foxit_reader:*:*:*:*:*:*:*:* | ||
<= 8.3.9.41099CPE matchmatch criteria | cpe:2.3:a:foxitsoftware:phantompdf:*:*:*:*:*:*:*:* | ||
>= 9.0.0, <= 9.4.1.16828CPE matchmatch criteria | cpe:2.3:a:foxitsoftware:phantompdf:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.0
CVSS:3.0/AV:L/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:H
No social media mentions found for this CVE.
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.2 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.