javahuang/SurveyKing

javahuang/SurveyKing

Releases3
Frequency2 months 1 day
Last Release
Stars3.98K
One command to deploy a more powerful, self‑hosted alternative to SurveyMonkey.

CVE History

CVEPublishedCVSS v3CVSS v2
9.1 CRITICAL

SurveyKing v1.3.1 was discovered to keep users' sessions active after logout. Related to an incomplete fix for CVE-2022-25590.

8.8 HIGH

An issue in SurveyKing v1.3.1 allows attackers to escalate privileges via re-using the session ID of a user that was deleted by an Admin.

4.3 MEDIUM

An issue in SurveyKing v1.3.1 allows attackers to execute a session replay attack after a user changes their password.

6.5 MEDIUM4.3 MEDIUM

SurveyKing v0.2.0 was discovered to retain users' session cookies after logout, allowing attackers to login to the system and access data using the browser cache when the user exits the application.