Vulnerability Description
The "remember me" functionality in login.php in Burden before 1.8.1 allows remote attackers to bypass authentication and gain privileges by setting the burden_user_rememberme cookie to 1.
CVSS Score
CRITICAL
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Burden Project | Burden | < 1.8.1 |
Related Weaknesses (CWE)
References
- http://www.exploit-db.com/exploits/30916ExploitThird Party AdvisoryVDB Entry
- http://www.securityfocus.com/archive/1/530703/100/0/threadedBroken LinkThird Party AdvisoryVDB Entry
- https://github.com/joshf/Burden/commit/edaa1bb8f73d6f3c8b2e78b67f1b40e02fccd0c1PatchThird Party Advisory
- https://github.com/joshf/Burden/issues/2Issue TrackingPatchThird Party Advisory
- https://github.com/joshf/Burden/releases/tag/1.8.1Release NotesThird Party Advisory
- https://www.htbridge.com/advisory/HTB23192Broken Link
- http://www.exploit-db.com/exploits/30916ExploitThird Party AdvisoryVDB Entry
- http://www.securityfocus.com/archive/1/530703/100/0/threadedBroken LinkThird Party AdvisoryVDB Entry
- https://github.com/joshf/Burden/commit/edaa1bb8f73d6f3c8b2e78b67f1b40e02fccd0c1PatchThird Party Advisory
- https://github.com/joshf/Burden/issues/2Issue TrackingPatchThird Party Advisory
- https://github.com/joshf/Burden/releases/tag/1.8.1Release NotesThird Party Advisory
- https://www.htbridge.com/advisory/HTB23192Broken Link
FAQ
What is CVE-2013-7137?
CVE-2013-7137 is a vulnerability with a CVSS score of 9.8 (CRITICAL). The "remember me" functionality in login.php in Burden before 1.8.1 allows remote attackers to bypass authentication and gain privileges by setting the burden_user_rememberme cookie to 1.
How severe is CVE-2013-7137?
CVE-2013-7137 has been rated CRITICAL with a CVSS base score of 9.8/10. This is considered a critical vulnerability requiring immediate attention.
Is there a patch for CVE-2013-7137?
Check the references section above for vendor advisories and patch information. Affected products include: Burden Project Burden.