Impact
The vulnerability is a missing signature validation in JSON Web Tokens used by the Otalio Ship Property Management System. When JWTs are not verified, an attacker who already has authenticated access can modify the token payload and re‑use it to elevate privileges. The affected code path is governed by CWE-347, which allows privilege escalation through tampered authentication credentials.
Affected Systems
The affected product is the Otalio Ship Property Management System. Only versions prior to 2.22.0 are impacted. Any deployment that relies on older releases is potentially vulnerable.
Risk and Exploitability
The CVSS score of 8.1 indicates a high severity level. EPSS is not available, and the vulnerability is not listed in the CISA KEV catalog. The likely attack vector is an authenticated attacker forging or altering JWTs; exploitation requires the attacker to already possess valid login credentials.
OpenCVE Enrichment