vendor:
Burden
by:
High-Tech Bridge Security Research Lab
9,8
CVSS
CRITICAL
Improper Authentication
287
CWE
Product Name: Burden
Affected Version From: 1.8
Affected Version To: 1.8
Patch Exists: YES
Related CWE: CVE-2013-7137
CPE: a:josh_fradley:burden
Metasploit:
N/A
Other Scripts:
N/A
Tags: N/A
CVSS Metrics: N/A
Nuclei References:
N/A
Nuclei Metadata: N/A
Platforms Tested: None
2013
Improper Authentication in Burden
The vulnerability exists due to insufficient authentication when handling "burden_user_rememberme" cookie parameter. A remote unauthenticated user can set "burden_user_rememberme" cookie to "1" and gain administrative access to the application.
Mitigation:
Update to Burden 1.8.1