CVE-2013-6788 describes an authentication bypass vulnerability in the Bitrix e-Store module before version 14.0.1 for Bitrix Site Manager. The vulnerability stems from the use of sequential values for the BITRIX_SM_SALE_UID cookie, making it susceptible to brute-force attacks. This vulnerability carries a CVSS score of 7.5 (High), indicating a critical risk. An unauthenticated attacker can exploit this remotely with low attack complexity to achieve partial confidentiality, integrity, and availability. There is no evidence of active exploitation, nor is exploit code publicly available in Metasploit, Nuclei, or ExploitDB. Community discussion and media coverage for this CVE are minimal.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
<= 14.0.0CPE matchmatch criteria | cpe:2.3:a:bitrix:bitrix_e-store_module:*:*:*:*:*:*:*:* |
CVSS version used by this source: 2.0
AV:N/AC:L/Au:N/C:P/I:P/A:P
No social media mentions found for this CVE.
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.1 Mastodon, and 0.4 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.