Vulnerabilities (CVE)

Filtered by vendor Surveyking Subscribe
Filtered by product Surveyking
Total 4 CVE
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2024-35048 1 Surveyking 1 Surveyking 2025-04-23 N/A 4.3 MEDIUM
An issue in SurveyKing v1.3.1 allows attackers to execute a session replay attack after a user changes their password.
CVE-2024-35049 1 Surveyking 1 Surveyking 2025-04-23 N/A 9.1 CRITICAL
SurveyKing v1.3.1 was discovered to keep users' sessions active after logout. Related to an incomplete fix for CVE-2022-25590.
CVE-2024-35050 1 Surveyking 1 Surveyking 2025-04-23 N/A 8.8 HIGH
An issue in SurveyKing v1.3.1 allows attackers to escalate privileges via re-using the session ID of a user that was deleted by an Admin.
CVE-2022-25590 1 Surveyking 1 Surveyking 2024-11-21 4.3 MEDIUM 6.5 MEDIUM
SurveyKing v0.2.0 was discovered to retain users' session cookies after logout, allowing attackers to login to the system and access data using the browser cache when the user exits the application.