CVE-2025-27920: Srimax Output Messenger Directory Traversal Vulnerability
Output Messenger before 2.0.63 was vulnerable to a directory traversal attack through improper file path handling. By using ../ sequences in parameters, attackers could access sensitive files outside the intended directory, potentially leading to configuration leakage or arbitrary file access.
Other sources
Srimax Output Messenger contains a directory traversal vulnerability that allows an attacker to access sensitive files outside the intended directory, potentially leading to configuration leakage or arbitrary file access.
— CISA
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-27920?
CVE-2025-27920 is considered a high-severity vulnerability due to its potential for directory traversal and sensitive file exposure.
How do I fix CVE-2025-27920?
To fix CVE-2025-27920, upgrade Output Messenger to version 2.0.63 or later to eliminate directory traversal vulnerabilities.
What types of attacks are possible with CVE-2025-27920?
CVE-2025-27920 allows attackers to perform directory traversal attacks that can lead to unauthorized access to sensitive files.
Which versions of Output Messenger are affected by CVE-2025-27920?
Output Messenger versions prior to 2.0.63 are affected by CVE-2025-27920.
What could be the impact of CVE-2025-27920 on my system?
The impact of CVE-2025-27920 could include configuration leakage, unauthorized file access, and potential compromise of sensitive data.