Show filters
2 Total Results
Displaying 1-2 of 2
Sort by:
Attacker Value
Unknown
CVE-2022-25590
Disclosure Date: March 25, 2022 (last updated February 23, 2025)
SurveyKing v0.2.0 was discovered to retain users' session cookies after logout, allowing attackers to login to the system and access data using the browser cache when the user exits the application.
0
Attacker Value
Unknown
CVE-2022-26249
Disclosure Date: March 24, 2022 (last updated February 23, 2025)
Survey King v0.3.0 does not filter data properly when exporting excel files, allowing attackers to execute arbitrary code or access sensitive information via a CSV injection attack.
0