PT-2025-19715 · Unknown · Output Messenger

Published

2025-05-05

·

Updated

2025-05-15

·

CVE-2025-27921

CVSS v3.1

6.1

Medium

VectorAV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
Name of the Vulnerable Software and Affected Versions Output Messenger versions prior to 2.0.63
Description A reflected cross-site scripting (XSS) issue was discovered, where unsanitized input could be injected into the web application’s response. This occurs when user-controlled input is reflected back into the browser without proper sanitization or encoding.
Recommendations For versions prior to 2.0.63, update to version 2.0.63 or later to resolve the issue. As a temporary workaround, consider implementing proper input sanitization and encoding to prevent user-controlled input from being injected into the web application’s response.

Fix

XSS

Weakness Enumeration

Related Identifiers

CVE-2025-27921

Affected Products

Output Messenger