What is CVE-2025-9210?
CVE-2025-9210: Missing JWT signature validation in Otalio Ship Property Management System allows authenticated attackers to escalate privileges by tampering with tokens. This affects versions before 2.22.0, and updating to the latest version is strongly recommended.
Azərbaycanca: CVE-2025-9210: Otalio Ship Property Management System versiyalarında JSON Web Token (JWT) imza yoxlanışının olmaması autentifikasiya olunmuş hücumçulara JWT-ləri manipulyasiya edərək imtiyazları artırmağa imkan verir. Əsasən gəmi əmlakı idarəetmə sisteminə təsir edir və dərhal 2.22.0 versiyasına yeniləmə etmək tövsiyə olunur.
Related CVEs
link basis: same weakness class CWE-287
FAQ2
Through which mechanism does CVE-2025-9210 allow privilege escalation in the Otalio system?
The vulnerability occurs due to missing JWT signature validation, allowing authenticated attackers to escalate privileges by tampering with tokens.
Which version is recommended for updating to fix CVE-2025-9210?
Updating to version 2.22.0 is strongly recommended.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.