CVE-2025-27920
Output Messenger before 2.0.63 was vulnerable to a directory traversal attack through improper file path handling. By using ../ sequences in parameters, attackers could access sensitive files outside the intended directory, potentially leading to configuration leakage or arbitrary file access.
Scoring
- Severity
- HIGH
- CVSS base score
- 7.2
- CVSS vector
- CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:L/I:L/A:N
- EPSS probability
- 1.85%
- CISA KEV
- Known exploited vulnerability
- CWE
- CWE-24
- Published
- 2025-05-05
- Last modified
- 2025-10-21
Affected products
- Srimax Output Messenger
Weakness type
Related vulnerabilities
- CVE-2024-6746 — NaiboWang EasySpider HTTP GET Request server.js path traversal
- CVE-2023-52076 — Remote Code Execution Vulnerability in Atril's EPUB ebook parsing
- CVE-2026-39813 — A path traversal: '../filedir' vulnerability in Fortinet FortiSandbox 5.0.0 through 5.0.5, FortiSandbox 4.4.0 through 4.
- CVE-2025-53513 — Zip slip vulnerability in Juju
- CVE-2024-23657 — Path Traversal: '../filedir' in Nuxt Devtools
- CVE-2021-26725 — Authenticated command path traversal on timezone settings in Guardian/CMC before 20.0.7.4
- CVE-2025-60344 — A path traversal (directory traversal) vulnerability in D-Link DSR series routers allows unauthenticated remote attacker
- CVE-2023-1800 — sjqzhang go-fastdfs File Upload uploa upload path traversal