Sceawere

Vulnerability Detail

CVE-2025-9211UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV

Otalio Stored XSS Privilege Escalation

Vulnerability Metadata

Severity
Medium
Score / CVSS
6.7
Creation Date
3h ago
Vendor
Otalio
Product
Ship Property Management System
Attack Type
CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
Vector String
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:L
Attack Complexity
LOW

Narrative and Response

Description

Unescaped stored values in application security page in Otalio Ship Property Management System versions before 2.22.0 allows authenticated attackers to escalate privileges via persistent cross-site scripting

Executive Summary

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Executive Summary Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Technical Details

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Detailed Technical Analysis Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Mitigations

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Remediation & Mitigations Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

References

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Intelligence References Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Additional Metadata

{
  "score": "6.7",
  "pubDate": "2026-08-18T19:16:44.103Z",
  "pubdate": "2026-08-18T19:16:44.103Z",
  "executiveSummary": "A stored cross-site scripting (XSS) vulnerability exists within the application security page of Otalio Ship Property Management System versions prior to 2.22.0.\nThe vulnerability arises from the lack of proper output encoding and input sanitization for stored values within the application security management interface.\nAuthenticated malicious actors with access to the vulnerable functionality can inject persistent arbitrary JavaScript payloads into stored parameters.\nWhen a privileged user or administrator subsequently views the compromised security page, the malicious script executes within the context of their session.\nThis behavior facilitates successful privilege escalation, allowing attackers to hijack administrative sessions, perform unauthorized administrative actions, or compromise the underlying security controls of the maritime property management platform.\nSuccessful exploitation requires authenticated access to the application and user interaction in the form of visiting the affected security page.",
  "technicalDetails": "The root cause of this vulnerability is improper neutralization of user-supplied input during web page generation, specifically concerning stored values rendered within the application security page of Otalio Ship Property Management System versions prior to 2.22.0.\nBecause the application fails to adequately sanitize or contextually encode stored data before rendering it in the Document Object Model (DOM), malicious input submitted by an attacker is persistently stored in the underlying database.\nThe exploitation lifecycle begins when an authenticated attacker submits a crafted payload containing malicious JavaScript into an input field or parameter associated with the application security page.\nThe application accepts and persists this unsanitized string into backend storage without applying validation checks or encoding mechanisms.\nSubsequently, when any authenticated user, particularly an administrator or high-privileged user, navigates to the affected application security page, the server retrieves the malicious record and renders it directly into the response payload.\nThe victim's web browser parses the response and executes the embedded script within the context of the victim's authenticated session, bypassing standard access controls.\nThe attack vector involves network exposure via the web application interface, requiring the attacker to possess prior authentication credentials.\nPrivilege requirements dictate that the attacker must have baseline authenticated access to interact with the vulnerable feature.\nPost-exploitation impact includes the execution of arbitrary JavaScript capable of performing actions on behalf of the victim, potentially leading to Session Hijacking, unauthorized modification of security configurations, and full administrative privilege escalation within the Otalio Ship Property Management System."
}
CVE-2025-9211: Otalio Stored XSS Privilege Escalation (MEDIUM Severity, CVSS: 6.7) - Sceawere