CVE Vulnerabilities

CVE-2024-35049

Insufficient Session Expiration

Published: May 14, 2024 | Modified: Apr 23, 2025
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
RedHat/V2
RedHat/V3
Ubuntu

SurveyKing v1.3.1 was discovered to keep users sessions active after logout. Related to an incomplete fix for CVE-2022-25590.

Weakness

According to WASC, “Insufficient Session Expiration is when a web site permits an attacker to reuse old session credentials or session IDs for authorization.”

Affected Software

Name Vendor Start Version End Version
Surveyking Surveyking 1.3.1 (including) 1.3.1 (including)

Potential Mitigations

References