CVE-2025-63563: Summerpearlgroup Vacation Rental Management Platform
Medium severity, CVSS 6.5. EPSS: 0.3% chance of exploitation in the next 30 days.
Summer Pearl Group Vacation Rental Management Platform prior to v1.0.2 does not properly invalidate active user sessions after a password change. This allows an attacker with a valid session token to maintain access to the account even after the legitimate user changes their password.
Affected products
- Summerpearlgroup Vacation Rental Management Platform: before 1.0.2 (fixed in 1.0.2)
Published 2025-10-31. Last modified 2026-06-17.