7.5
CVSSv2

CVE-2013-6788

Published: 30/05/2014 Updated: 26/06/2014
CVSS v2 Base Score: 7.5 | Impact Score: 6.4 | Exploitability Score: 10
VMScore: 668
Vector: AV:N/AC:L/Au:N/C:P/I:P/A:P

Vulnerability Summary

The Bitrix e-Store module prior to 14.0.1 for Bitrix Site Manager uses sequential values for the BITRIX_SM_SALE_UID cookie, which makes it easier for remote malicious users to guess the cookie value and bypass authentication via a brute force attack.

Vulnerable Product Search on Vulmon Subscribe to Product

bitrix bitrix_e-store_module

Exploits

High-Tech Bridge Security Research Lab discovered a vulnerability in Bitrix Site Manager version 12513 that can be exploited to spoof a user's identity and read, modify or delete pre-ordered items in customer's basket ...