CVE-2025-9210: Missing JSON Web Token signature validation in Otalio Ship Property Management System
Missing signature validation in JSON Web Tokens in Otalio Ship Property Management System versions before 2.22.0 allows authenticated attackers to escalate privileges via tampering with JWTs
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
Otalio Ship Property Management Systemto a version that resolves this vulnerability.Fixed in 2.22.0
Event History
Frequently Asked Questions
What level of access does an attacker need to exploit this issue?
An attacker must already be authenticated with a valid account. Exploitation can be performed remotely with low complexity and does not require user interaction.
Which versions should be remediated?
Versions before 2.22.0 are affected. Upgrading to version 2.22.0 or later addresses the affected version range described.
What could an attacker achieve?
Successful exploitation allows an authenticated attacker to escalate privileges by tampering with JSON Web Tokens, with high impacts to confidentiality and integrity. Availability impact is listed as none.