CVE-2013-7137
CRITICALburden < 1.8.1 - Unauthenticated Authentication Bypass via Remember Me Cookie
Title source: llmExploitation Summary
EIP tracks 1 public exploit for CVE-2013-7137. PoCs published by High-Tech Bridge SA.
AI-analyzed exploit summary The advisory describes an authentication bypass vulnerability in Burden 1.8, where setting the 'burden_user_rememberme' cookie to '1' grants administrative access. The exploit is trivial and requires no authentication.
Description
The "remember me" functionality in login.php in Burden before 1.8.1 allows remote attackers to bypass authentication and gain privileges by setting the burden_user_rememberme cookie to 1.
Exploits (1)
The advisory describes an authentication bypass vulnerability in Burden 1.8, where setting the 'burden_user_rememberme' cookie to '1' grants administrative access. The exploit is trivial and requires no authentication.
References (6)
Scores
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H