ZeroHour

CVE-2022-25590

PoC
CVSS 3.1
6.5 medium
EPSS
1%p69
Published
()
Modified
Description

SurveyKing v0.2.0 was discovered to retain users' session cookies after logout, allowing attackers to login to the system and access data using the browser cache when the user exits the application.

Vendors
surveyking
Products
surveyking
Weakness
CWE-613
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N

In the news

No ingested article mentions this CVE yet.