Junglewise Threat Intelligence

CVE-2025-8664: Saysis StarCities E-Municipality Management XSS

CVE-2025-8664 · Severity: medium · CVSS 6.3 · Published 2025-09-19

Executive brief

StarCities E-Municipality Management, a software suite used by local governments to manage municipal services and citizen interactions, is vulnerable to a security flaw that allows attackers to inject malicious scripts into web pages. If a user views a compromised page, an attacker could potentially steal session information, impersonate the user, or redirect them to fraudulent websites. This could lead to unauthorized access to municipal administrative tools or the compromise of citizen data.

Technical details

A Cross-Site Scripting (XSS) vulnerability exists in Saysis StarCities E-Municipality Management due to improper neutralization of user-supplied input during web page generation (CWE-79). The vulnerability is exploitable via the network without authentication, though it requires a victim to interact with a malicious link or page (User Interaction: Required). Successful exploitation allows an attacker to execute arbitrary JavaScript in the context of the victim's browser session, potentially leading to session hijacking or unauthorized actions. The issue is addressed in updates released on or after August 25, 2025.

Affected products

  • Saysis Computer Systems Trade Ltd. Co. StarCities E-Municipality Management before 20250825

Timeline

  • 2025-08-25: patched: Versions before this date are affected.
  • 2025-09-19: disclosed
  • 2025-09-19: advisory

References