CVE-2024-35048
CVE-2024-35048 in SurveyKing v1.3.1 allows for session replay attacks, even after a user changes their password. This vulnerability lets attackers potentially impersonate legitimate users by replaying captured session data. Although the CVSS score is 4.3, indicating moderate severity, the SOCRadar Vulnerability Risk Score (SVRS) of 30 suggests a lower immediate risk compared to critical vulnerabilities. The weakness stems from improper session invalidation following password changes, falling under CWE-613 (Improper Session Management). While not immediately critical, the 'In The Wild' tag means attackers are aware and are actively attempting to leverage the issue. Addressing this vulnerability should be prioritized to prevent potential account compromise and maintain user security. This is significant because successful exploitation could lead to unauthorized access and data breaches within the SurveyKing application.
Indicators of Compromise
Exploits
News
Social Media
Affected Software
References
CWE Details
CVE Radar
Real-time CVE Intelligence & Vulnerability Management Platform
CVE Radar provides comprehensive vulnerability intelligence by monitoring CVE databases, security advisories, and threat feeds. Get instant updates on new vulnerabilities, exploit details, and mitigation strategies specific to your assets.