CVE-2025-9211: Cross-site scripting in Otalio Ship Property Management System
Unescaped stored values in application security page in Otalio Ship Property Management System versions before 2.22.0 allows authenticated attackers to escalate privileges via persistent cross-site scripting
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
Otalio Ship Property Management Systemto a version that resolves this vulnerability.Fixed in 2.22.0
Event History
Frequently Asked Questions
What level of access does an attacker need to exploit this issue?
Attackers need an authenticated account with high privileges (PR:H). Exploitation does not require user interaction and can be performed over the network.
Which deployments are affected?
The affected versions are Otalio Ship Property Management System releases before 2.22.0. Systems running version 2.22.0 or later are not identified as affected by the provided information.
How can administrators check for signs of exposure?
The vulnerable input is stored on the application's security page, where unescaped values can execute persistent script. Review values saved on that page for unexpected or untrusted content.