Vulnerability Description
Output Messenger before 2.0.63 was vulnerable to a directory traversal attack through improper file path handling. By using ../ sequences in parameters, attackers could access sensitive files outside the intended directory, potentially leading to configuration leakage or arbitrary file access.
CVSS Score
HIGH
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Srimax | Output Messenger | < 2.0.63 |
Related Weaknesses (CWE)
References
- https://www.outputmessenger.com/cve-2025-27920/Vendor Advisory
- https://www.srimax.com/products-2/output-messenger/Product
- https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2025-US Government Resource
- https://www.microsoft.com/en-us/security/blog/2025/05/12/marbled-dust-leverages-MitigationThird Party Advisory
FAQ
What is CVE-2025-27920?
CVE-2025-27920 is a vulnerability with a CVSS score of 7.2 (HIGH). Output Messenger before 2.0.63 was vulnerable to a directory traversal attack through improper file path handling. By using ../ sequences in parameters, attackers could access sensitive files outside ...
How severe is CVE-2025-27920?
CVE-2025-27920 has been rated HIGH with a CVSS base score of 7.2/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2025-27920?
Check the references section above for vendor advisories and patch information. Affected products include: Srimax Output Messenger.