ZeroHour

CVE-2025-9210

CVSS 3.1
8.1 high
EPSS
<1%p5
Published
()
Modified
Description

Missing signature validation in JSON Web Tokens in Otalio Ship Property Management System versions before 2.22.0 allows authenticated attackers to escalate privileges via tampering with JWTs

Weakness
CWE-347
Vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N

In the news

No ingested article mentions this CVE yet.