PT-2024-26297 · Unknown · Surveyking

Menghaining

·

Published

2024-05-13

·

Updated

2024-07-03

·

CVE-2024-35049

CVSS v3.1

9.1

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N
Name of the Vulnerable Software and Affected Versions SurveyKing version 1.3.1
Description The issue allows users' sessions to remain active after logout, which is related to an incomplete fix.
Recommendations For SurveyKing version 1.3.1, consider implementing a full logout mechanism to invalidate user sessions upon logout as a temporary workaround until a complete fix is available.

Exploit

Fix

Insufficient Session Expiration

Weakness Enumeration

Related Identifiers

CVE-2024-35049

Affected Products

Surveyking