What is CVE-2025-9211?
Unescaped stored values in the application security page of Otalio Ship Property Management System versions before 2.22.0 allow authenticated attackers to escalate privileges via persistent cross-site scripting. Affected users should immediately update to version 2.22.0 or later.
Azərbaycanca: Otalio Ship Property Management System-in 2.22.0-dan əvvəlki versiyalarında təhlükəsizlik səhifəsində saxlanılan dəyərlərin qaçırılmaması (unescaped stored values) autentifikasiya olunmuş təcavüzkarlara persistent cross-site scripting (XSS) vasitəsilə imtiyazları yüksəltməyə imkan verir. Təsirə məruz qalan sistemlərdə istifadəçilər dərhal 2.22.0 və ya daha yeni versiyaya yeniləmə etməlidir.
Related CVEs
link basis: same weakness class CWE-79
FAQ1
Does exploiting CVE-2025-9211 require the attacker to be authenticated?
Yes, this vulnerability allows authenticated attackers to perform persistent XSS.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.