Junglewise Threat Intelligence

CVE-2025-13183: Hotech Otello Stored XSS

CVE-2025-13183 · Severity: high · CVSS 7.3 · Published 2025-12-23

Executive brief

Hotech Otello, a hospitality management software suite, contains a security vulnerability that allows attackers to inject malicious scripts into the system. If an authorized user views the affected area, these scripts can execute in their browser, potentially leading to the theft of session cookies, unauthorized access to guest data, or the performance of actions on behalf of the user. This could compromise the integrity of hotel operations and sensitive customer information.

Technical details

A Stored Cross-Site Scripting (XSS) vulnerability exists in Hotech Otello versions 2.4.0 through 2.4.3. The flaw stems from the application's failure to properly sanitize user-supplied input before storing it and subsequently rendering it in web pages. An authenticated attacker with low privileges can inject malicious JavaScript into the application database. When other users, such as administrators, view the compromised page, the script executes within their browser context. This can lead to session hijacking or unauthorized data exfiltration. The issue is resolved in version 2.4.4.

Affected products

  • Hotech Software Inc. Otello from 2.4.0 before 2.4.4

Timeline

  • 2025-12-23: advisory: Initial advisory published by TR-CERT

References