PT-2022-17387 · Unknown · Surveyking

Kpa1Onop

·

Published

2022-03-25

·

Updated

2024-05-13

·

CVE-2022-25590

CVSS v3.1

6.5

Medium

VectorAV:N/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N
Name of the Vulnerable Software and Affected Versions SurveyKing version 0.2.0
Description The issue allows attackers to login to the system and access data using the browser cache when the user exits the application, due to the retention of users' session cookies after logout.
Recommendations For SurveyKing version 0.2.0, consider clearing the browser cache after logout as a temporary workaround to minimize the risk of exploitation. Restrict access to sensitive data until a proper fix is implemented to prevent session cookie retention. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

Insufficient Session Expiration

Weakness Enumeration

Related Identifiers

CVE-2022-25590

Affected Products

Surveyking