First published: Fri May 30 2014(Updated: )
The Bitrix e-Store module before 14.0.1 for Bitrix Site Manager uses sequential values for the BITRIX_SM_SALE_UID cookie, which makes it easier for remote attackers to guess the cookie value and bypass authentication via a brute force attack.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Bitrix | <=14.0.0 | |
Bitrix Site Manager | <=12.5.13 | |
All of | ||
Bitrix | <=14.0.0 | |
Bitrix Site Manager | <=12.5.13 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2013-6788 is rated as a medium severity vulnerability due to its potential for exploitation through brute force attacks.
To fix CVE-2013-6788, upgrade the Bitrix e-Store module to version 14.0.1 or later.
CVE-2013-6788 affects the Bitrix e-Store module versions prior to 14.0.1.
Yes, CVE-2013-6788 can potentially allow remote attackers to bypass authentication and gain unauthorized access.
CVE-2013-6788 can be exploited through brute force attacks that target the sequential values of the BITRIX_SM_SALE_UID cookie.