Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2025-27921

Опубликовано: 05 мая 2025
Источник: nvd
CVSS3: 6.1
EPSS Низкий

Описание

A reflected cross-site scripting (XSS) vulnerability was discovered in Output Messenger before 2.0.63, where unsanitized input could be injected into the web application’s response. This vulnerability occurs when user-controlled input is reflected back into the browser without proper sanitization or encoding.

Уязвимые конфигурации

Конфигурация 1
cpe:2.3:a:srimax:output_messenger:*:*:*:*:*:*:*:*
Версия до 2.0.63 (исключая)

EPSS

Процентиль: 14%
0.00046
Низкий

6.1 Medium

CVSS3

Дефекты

CWE-79

Связанные уязвимости

CVSS3: 6.1
github
9 месяцев назад

A reflected cross-site scripting (XSS) vulnerability was discovered in Output Messenger before 2.0.63, where unsanitized input could be injected into the web application’s response. This vulnerability occurs when user-controlled input is reflected back into the browser without proper sanitization or encoding.

EPSS

Процентиль: 14%
0.00046
Низкий

6.1 Medium

CVSS3

Дефекты

CWE-79