#VU109018 Path traversal in Output Messenger - CVE-2025-27920
Published: May 13, 2025
Output Messenger
Srimax Software System
Description
The vulnerability allows a remote user to perform directory traversal attacks.
The vulnerability exists due to input validation error when processing directory traversal sequences. A remote authenticated user can upload malicious files to an arbitrary location on the system and execute them, leading to full system compromise.
Note, the vulnerability is being actively exploited in the wild.