CVE-2025-27920highunder attackCWE-24

CVE-2025-27920: high-severity vulnerability in Srimax Output Messenger

Published · Updated

51Vexday Risk Score

Prioritize patching. It under exploitation confirmed by CISA.

ssvc Actcvss 7.2epss 1.9%
from disclosure to weapon
Published on NVDMay 5
CISA KEV+14d
exploitation probability
1.9%top 21% of all CVEs
observed exploitation
yesCISA + VulnCheck
Action required by CISAfederal deadline: 2025-06-09

Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.

In short

Output Messenger versions before 2.0.63 allow attackers to access files outside the intended folder using path tricks (../ sequences), potentially exposing sensitive configuration files and other private data.

Technical detail

Directory traversal vulnerability in Output Messenger <2.0.63 via improper file path validation in parameters. Attackers can inject ../ sequences to traverse directories and read arbitrary files, compromising confidentiality of configuration and sensitive data without requiring authentication.

Summary generated and translated by AI from the official description.

The full analysis of this CVE is available in Portuguese →

Output Messenger before 2.0.63 was vulnerable to a directory traversal attack through improper file path handling. By using ../ sequences in parameters, attackers could access sensitive files outside the intended directory, potentially leading to configuration leakage or arbitrary file access.
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:L/I:L/A:N