CVE-2025-63563

S

ummer Pearl Group Vacation Rental Management Platform prior to v1.0.2 does not properly invalidate active user sessions after a password change. This allows an attacker with a valid session token to maintain access to the account even after the legitimate user changes their password.

Configurations

Configuration 1 (hide)

cpe:2.3:a:summerpearlgroup:vacation_rental_management_platform:*:*:*:*:*:*:*:*

History

05 Nov 2025, 19:10

Type Values Removed Values Added
First Time Summerpearlgroup vacation Rental Management Platform
Summerpearlgroup
CPE cpe:2.3:a:summerpearlgroup:vacation_rental_management_platform:*:*:*:*:*:*:*:*
References () https://github.com/Stolichnayer/Summer-Pearl-Group-Insufficient-Session-Expiration - () https://github.com/Stolichnayer/Summer-Pearl-Group-Insufficient-Session-Expiration - Product

03 Nov 2025, 21:19

Type Values Removed Values Added
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 6.5
CWE CWE-286

31 Oct 2025, 21:15

Type Values Removed Values Added
New CVE

Information

Published : 2025-10-31 21:15

Updated : 2025-11-05 19:10


NVD link : CVE-2025-63563

Mitre link : CVE-2025-63563

CVE.ORG link : CVE-2025-63563


JSON object : View

CWE
CWE-286

Incorrect User Management