THREAT OPS › Threat News › Security advisory: Pre-authentication SYSTEM RCE (Zip-Slip plugin planting) in Output Messenger Server 2.0.x (>= 2.0.63) (Srimax Software (Output Technology))
Security advisory: Pre-authentication SYSTEM RCE (Zip-Slip plugin planting) in Output Messenger Server 2.0.x (>= 2.0.63) (Srimax Software (Output Technology))
<p>Posted by disclosure via Fulldisclosure on Aug 17</p>0day Rubbish Research Team is publicly disclosing a vulnerability in Output Messenger Server 2.0.x (>= 2.0.63) (Srimax <br /> Software (Output Technology)). The research is published and a proof-of-concept is available.<br /> <br /> Pre-authentication SYSTEM RCE (Zip-Slip plugin planting) (CVSS 9.8, pre-authentication)<br /> <br /> Output
MITRE ATT&CK techniques
- CredentialsT1589.001
Original source: https://seclists.org/fulldisclosure/2026/Aug/65