---
id: CVE-2022-25590
title: >-
  SurveyKing v0.2.0 was discovered to retain users' session cookies after
  logout, allowing attackers to login to the system and access data using the
  browser cache when the user exits the application.
summary: >-
  SurveyKing v0.2.0 was discovered to retain users' session cookies after
  logout, allowing attackers to login to the system and access data using the
  browser cache when the user exits the application.
severity: medium
cvss: 6.5
cvssVector: 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N'
cwe:
  - CWE-613
vendor: surveyking
product: surveyking
affected:
  - surveyking = 0.2.0
published: '2022-03-25'
updated: '2026-07-05'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2022-25590'
references:
  - url: 'https://github.com/javahuang/SurveyKing'
    label: cve@mitre.org
  - url: 'https://github.com/javahuang/SurveyKing/issues/7'
    label: cve@mitre.org
  - url: 'http://surveyking.com'
    label: af854a3a-2127-422b-91ae-364da2661108
  - url: 'https://github.com/javahuang/SurveyKing'
    label: af854a3a-2127-422b-91ae-364da2661108
  - url: 'https://github.com/javahuang/SurveyKing/issues/7'
    label: af854a3a-2127-422b-91ae-364da2661108
tags:
  - nvd
epss: 0.01309
epssPercentile: 0.69432
ingestedAt: '2026-07-06T17:03:24.110Z'
---

## Overview

SurveyKing v0.2.0 was discovered to retain users' session cookies after logout, allowing attackers to login to the system and access data using the browser cache when the user exits the application.

## Affected

- `surveyking = 0.2.0`

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
