SEPTEMBER 18, 2026
Live Feed
Back to database
Case File

CVE-2025-9211

MEDIUM · CVSS 6.7 EPSS 0.27% Public Exploit

Source: NVD + CISA KEV + EPSS · Published 2026-08-18 · Last synced 2026-09-17

CyberRota Analysis

AI-Generated

The Otalio Ship Property Management System versions prior to 2.22.0 are vulnerable due to unescaped stored values on the application security page, enabling authenticated attackers to exploit persistent cross-site scripting (XSS) vulnerabilities for privilege escalation. This could allow attackers to gain unauthorized access to sensitive functionalities and data within the application. Organizations using affected versions should prioritize patching to mitigate potential security risks.

Public Exploit Signal

A public exploit, PoC, GitHub repository or Metasploit reference was detected for this CVE.

GitHub PoC Links

Note: these links are listed for security research and verification purposes only.

CVE
CVE-2025-9211
Severity
MEDIUM
CVSS
6.7
EPSS
0.27%

Original NVD Description

Unescaped stored values in application security page in Otalio Ship Property Management System versions before 2.22.0 allows authenticated attackers to escalate privileges via persistent cross-site scripting