CVE Vulnerabilities

CVE-2024-35050

Insufficient Session Expiration

Published: May 14, 2024 | Modified: Apr 23, 2025
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
RedHat/V2
RedHat/V3
Ubuntu

An issue in SurveyKing v1.3.1 allows attackers to escalate privileges via re-using the session ID of a user that was deleted by an Admin.

Weakness

According to WASC, “Insufficient Session Expiration is when a web site permits an attacker to reuse old session credentials or session IDs for authorization.”

Affected Software

Name Vendor Start Version End Version
Surveyking Surveyking 1.3.1 (including) 1.3.1 (including)

Potential Mitigations

References