Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
No advisories yet.
Tue, 18 Aug 2026 19:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Tue, 18 Aug 2026 18:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Unescaped stored values in application security page in Otalio Ship Property Management System versions before 2.22.0 allows authenticated attackers to escalate privileges via persistent cross-site scripting | |
| Title | Cross-site scripting in Otalio Ship Property Management System | |
| Weaknesses | CWE-79 | |
| References |
| |
| Metrics |
cvssV3_1
|
Subscriptions
No data.
Status: PUBLISHED
Assigner: Mandiant
Published:
Updated: 2026-08-18T18:51:43.637Z
Reserved: 2025-08-19T19:20:03.110Z
Link: CVE-2025-9211
Updated: 2026-08-18T18:51:39.331Z
Status : Received
Published: 2026-08-18T19:16:44.103
Modified: 2026-08-18T19:16:44.103
Link: CVE-2025-9211
No data.
OpenCVE Enrichment
Updated: 2026-08-18T19:30:04Z