A reflected cross-site scripting (XSS) vulnerability was discovered in Output Messenger before 2.0.63, where unsanitized input could be injected into the web application’s response. This vulnerability occurs when user-controlled input is reflected back into the browser without proper sanitization or encoding.
Advisories
Source ID Title
EUVD EUVD EUVD-2025-13454 A reflected cross-site scripting (XSS) vulnerability was discovered in Output Messenger before 2.0.63, where unsanitized input could be injected into the web application’s response. This vulnerability occurs when user-controlled input is reflected back into the browser without proper sanitization or encoding.
Fixes

Solution

No solution given by the vendor.


Workaround

No workaround given by the vendor.

History

Sat, 12 Jul 2025 13:45:00 +0000

Type Values Removed Values Added
Metrics epss

{'score': 0.00035}

epss

{'score': 0.00041}


Fri, 13 Jun 2025 19:00:00 +0000

Type Values Removed Values Added
First Time appeared Srimax
Srimax output Messenger
CPEs cpe:2.3:a:srimax:output_messenger:*:*:*:*:*:*:*:*
Vendors & Products Srimax
Srimax output Messenger

Mon, 05 May 2025 16:45:00 +0000

Type Values Removed Values Added
Weaknesses CWE-79
Metrics cvssV3_1

{'score': 6.1, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N'}


Mon, 05 May 2025 15:45:00 +0000

Type Values Removed Values Added
Description A reflected cross-site scripting (XSS) vulnerability was discovered in Output Messenger before 2.0.63, where unsanitized input could be injected into the web application’s response. This vulnerability occurs when user-controlled input is reflected back into the browser without proper sanitization or encoding.
References

cve-icon MITRE

Status: PUBLISHED

Assigner: mitre

Published:

Updated: 2025-05-05T15:57:38.122Z

Reserved: 2025-03-10T00:00:00.000Z

Link: CVE-2025-27921

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Analyzed

Published: 2025-05-05T16:15:51.143

Modified: 2025-06-13T18:40:52.873

Link: CVE-2025-27921

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

No data.