CVE Vulnerabilities

CVE-2024-35048

Insufficient Session Expiration

Published: May 14, 2024 | Modified: Apr 23, 2025
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
RedHat/V2
RedHat/V3
Ubuntu

An issue in SurveyKing v1.3.1 allows attackers to execute a session replay attack after a user changes their password.

Weakness

According to WASC, “Insufficient Session Expiration is when a web site permits an attacker to reuse old session credentials or session IDs for authorization.”

Affected Software

Name Vendor Start Version End Version
Surveyking Surveyking 1.3.1 (including) 1.3.1 (including)

Potential Mitigations

References