HIGH

CVE-2025-27920

Srimax Output Messenger 2025-05-05 CVSS v3.1
CVSS
8.8
KEV

Description

Output Messenger before 2.0.63 was vulnerable to a directory traversal attack through improper file path handling. By using ../ sequences in parameters, attackers could access sensitive files outside the intended directory, potentially leading to configuration leakage or arbitrary file access.

Summary dbcve.org

Output Messenger before version 2.0.63 contains a directory traversal vulnerability caused by improper file path handling. Attackers can inject ../ sequences into parameters to escape the intended directory and access sensitive files outside the web root, potentially exposing configuration files or other confidential data.

Mitigation

Upgrade to version 2.0.63 or later which contains the fix for this vulnerability. Additionally, implement strict input validation and path canonicalization to verify that resolved file paths remain within the intended directory.

Weakness (CWE)

CWE-24

EPSS Score

1.86%
Probability of exploitation in next 30 days
78.2th percentile

References

View on dbcve.org
Base CVE data derived from NVD (public domain). Enrichment by dbcve.org (CC-BY-4.0). Fetched via API.
Back to CVE