Vulnerabilities
Vulnerable Software
Srimax:  >> Output Messenger  Security Vulnerabilities
A reflected cross-site scripting (XSS) vulnerability was discovered in Output Messenger before 2.0.63, where unsanitized input could be injected into the web application’s response. This vulnerability occurs when user-controlled input is reflected back into the browser without proper sanitization or encoding.
CVSS Score
6.1
EPSS Score
0.001
Published
2025-05-05
CVE-2025-27920
Known exploited
Output Messenger before 2.0.63 was vulnerable to a directory traversal attack through improper file path handling. By using ../ sequences in parameters, attackers could access sensitive files outside the intended directory, potentially leading to configuration leakage or arbitrary file access.
CVSS Score
7.2
EPSS Score
0.607
Published
2025-05-05


Contact Us

Shodan ® - All rights reserved