PT-2022-17387 · Unknown · Surveyking
Kpa1Onop
·
Published
2022-03-25
·
Updated
2024-05-13
·
CVE-2022-25590
CVSS v3.1
6.5
Medium
| Vector | AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N |
Name of the Vulnerable Software and Affected Versions
SurveyKing version 0.2.0
Description
The issue allows attackers to login to the system and access data using the browser cache when the user exits the application, due to the retention of users' session cookies after logout.
Recommendations
For SurveyKing version 0.2.0, consider clearing the browser cache after logout as a temporary workaround to minimize the risk of exploitation. Restrict access to sensitive data until a proper fix is implemented to prevent session cookie retention. At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Exploit
Insufficient Session Expiration
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Surveyking