CVE-2025-27920: high-severity vulnerability in Srimax Output Messenger
Published · Updated
Prioritize patching. It under exploitation confirmed by CISA.
Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.
Output Messenger versions before 2.0.63 allow attackers to access files outside the intended folder using path tricks (../ sequences), potentially exposing sensitive configuration files and other private data.
Directory traversal vulnerability in Output Messenger <2.0.63 via improper file path validation in parameters. Attackers can inject ../ sequences to traverse directories and read arbitrary files, compromising confidentiality of configuration and sensitive data without requiring authentication.
The full analysis of this CVE is available in Portuguese →