9.8
CVSSv3

CVE-2013-7137

Published: 26/01/2014 Updated: 06/04/2022
CVSS v2 Base Score: 7.5 | Impact Score: 6.4 | Exploitability Score: 10
CVSS v3 Base Score: 9.8 | Impact Score: 5.9 | Exploitability Score: 3.9
VMScore: 755
Vector: AV:N/AC:L/Au:N/C:P/I:P/A:P

Vulnerability Summary

The "remember me" functionality in login.php in Burden prior to 1.8.1 allows remote malicious users to bypass authentication and gain privileges by setting the burden_user_rememberme cookie to 1.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

burden project burden

Exploits

Advisory ID: HTB23192 Product: Burden Vendor: Josh Fradley Vulnerable Version(s): 18 and probably prior Tested Version: 18 Advisory Publication: December 18, 2013 [without technical details] Vendor Notification: December 18, 2013 Vendor Patch: December 18, 2013 Public Disclosure: January 8, 2014 Vulnerability Type: Improper Authentication [C ...
Burden version 18 has an authentication flaw that can be exploited by a remote non-authenticated attacker to gain administrative access ...