Description
In the PdfViewer component, a Cross-Site Scripting (XSS) vulnerability is possible if a specially-crafted document has already been loaded and the user engages with a tool that requires the DOM to be re-rendered.
Problem types
CWE-79 Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting')
Product status
2024.4.1112 (custom)
18.5.0 (semver)
5.10.0 (semver)
2024.4.1112 (custom)
2024.4.1112 (custom)
3.6.0 (semver)
References
www.telerik.com/...pdfviewer-xss-vulnerability-cve-2025-6725
www.telerik.com/...e/kb-security-pdfviewer-xss-cve-2025-6725
www.telerik.com/...e/kb-security-pdfviewer-xss-cve-2025-6725
www.telerik.com/...e/kb-security-pdfviewer-xss-cve-2025-6725
www.telerik.com/...e/kb-security-pdfviewer-xss-cve-2025-6725
www.telerik.com/...e/kb-security-pdfviewer-xss-cve-2025-6725