CVE-2022-25590

Source
https://cve.org/CVERecord?id=CVE-2022-25590
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2022-25590.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2022-25590
Published
2022-03-25T18:50:11Z
Modified
2026-07-15T01:49:10.205205586Z
Summary
[none]
Details

SurveyKing v0.2.0 was discovered to retain users' session cookies after logout, allowing attackers to login to the system and access data using the browser cache when the user exits the application.

Database specific
{
    "osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2022/25xxx/CVE-2022-25590.json",
    "cna_assigner": "mitre"
}
References

Affected packages

Git / github.com/javahuang/surveyking

Affected ranges

Type
GIT
Repo
https://github.com/javahuang/surveyking
Events
Database specific
{
    "cpe": "cpe:2.3:a:surveyking:surveyking:0.2.0:*:*:*:*:*:*:*",
    "source": "CPE_STRING",
    "extracted_events": [
        {
            "introduced": "0.2.0"
        },
        {
            "last_affected": "0.2.0"
        }
    ]
}

Affected versions

0.*
0.2.0
v0.*
v0.2.0

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2022-25590.json"