CVE Vulnerabilities

CVE-2025-63563

Incorrect User Management

Published: Oct 31, 2025 | Modified: Nov 05, 2025
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
RedHat/V2
RedHat/V3
Ubuntu

Summer Pearl Group Vacation Rental Management Platform prior to v1.0.2 does not properly invalidate active user sessions after a password change. This allows an attacker with a valid session token to maintain access to the account even after the legitimate user changes their password.

Weakness

The product does not properly manage a user within its environment.

Affected Software

Name Vendor Start Version End Version
Vacation_rental_management_platform Summerpearlgroup * 1.0.2 (excluding)

References