Flo354

2 exploits Active since Aug 2025
CVE-2025-51306 WRITEUP MEDIUM WRITEUP
Gatling Enterprise <1.25.0 - Info Disclosure
In Gatling Enterprise versions below 1.25.0, a user logging-out can still use his session token to continue using the application without expiration, due to incorrect session management.
CVSS 6.5
CVE-2025-51308 WRITEUP MEDIUM WRITEUP
Gatling Enterprise <1.25.0 - Info Disclosure
In Gatling Enterprise versions below 1.25.0, a low-privileged user that does not hold the role "admin" could perform a REST API call on read-only endpoints, allowing him to collect some information, due to missing authorization checks.
CVSS 5.3