CVE-2025-27921
05.05.2025, 16:15
A reflected cross-site scripting (XSS) vulnerability was discovered in Output Messenger before 2.0.63, where unsanitized input could be injected into the web applications response. This vulnerability occurs when user-controlled input is reflected back into the browser without proper sanitization or encoding.
Vendor | Product | Version |
---|---|---|
srimax | output_messenger | 𝑥 < 2.0.63 |
𝑥
= Vulnerable software versions