# CVE-2025-9211

## Summary

- **CVE ID:** CVE-2025-9211
- **Severity:** MEDIUM
- **CVSS Score:** 6.7 (CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:L)
- **CWE:** CWE-79
- **Published:** Aug 18, 2026
- **Last Modified:** Aug 18, 2026

## Description

Unescaped stored values in application security page in Otalio Ship Property Management System versions before 2.22.0 allows authenticated attackers to escalate privileges via persistent cross-site scripting

## Affected Products

- Otalio — Ship Property Management System (0)

## References

- [CNA](https://www.otalio.com/solutions/)
- [CNA](https://github.com/mandiant/Vulnerability-Disclosures/blob/master/2026/MNDT-2026-0024.md)

## Exploitation Prediction (EPSS)

- **EPSS Score:** 0.27%
- **EPSS Percentile:** 19.4

---
_Exported from OnDuty AI Vulnerability Intelligence on 2026-09-18._