CVE-2013-6788: High severity Bitrix Bitrix e-Store module vulnerability
The Bitrix e-Store module before 14.0.1 for Bitrix Site Manager uses sequential values for the BITRIXSMSALEUID cookie, which makes it easier for remote attackers to guess the cookie value and bypass authentication via a brute force attack.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2013-6788?
CVE-2013-6788 is rated as a medium severity vulnerability due to its potential for exploitation through brute force attacks.
How do I fix CVE-2013-6788?
To fix CVE-2013-6788, upgrade the Bitrix e-Store module to version 14.0.1 or later.
What software is affected by CVE-2013-6788?
CVE-2013-6788 affects the Bitrix e-Store module versions prior to 14.0.1.
Can CVE-2013-6788 lead to unauthorized access?
Yes, CVE-2013-6788 can potentially allow remote attackers to bypass authentication and gain unauthorized access.
What type of attacks can exploit CVE-2013-6788?
CVE-2013-6788 can be exploited through brute force attacks that target the sequential values of the BITRIX_SM_SALE_UID cookie.