CVE-2025-27920
HIGH KEVSrimax Output Messenger < 2.0.63 - Path Traversal
Title source: ruleDescription
Output Messenger before 2.0.63 was vulnerable to a directory traversal attack through improper file path handling. By using ../ sequences in parameters, attackers could access sensitive files outside the intended directory, potentially leading to configuration leakage or arbitrary file access.
References (4)
Scores
CVSS v3
7.2
EPSS
0.5015
EPSS Percentile
97.8%
Attack Vector
NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:L/I:L/A:N
Details
CISA KEV
2025-05-19
VulnCheck KEV
2025-05-12
ENISA EUVD
EUVD-2025-13464
CWE
CWE-24
Status
published
Products (1)
srimax/output_messenger
< 2.0.63
Published
May 05, 2025
KEV Added
May 19, 2025
Tracked Since
Feb 18, 2026