Skip to content

CVE-2013-6788

The Bitrix e-Store module before 14.0.1 for Bitrix Site Manager uses sequential values for the BITRIX_SM_SALE_UID cookie, which makes it easier for remote attackers to guess the cookie value and bypass authentication via a brute force attack.

Ver en NVD

Severidad

N/A

EPSS

Probabilidad de explotación (próx. 30 días): 0.0043 (0.4%)
Percentil: 62.7%
EPSS: 2026-05-06

Afecta

bitrix:bitrix_e-store_modulebitrix:bitrix_site_manager

Descripción técnica

The Bitrix e-Store module before 14.0.1 for Bitrix Site Manager uses sequential values for the BITRIX_SM_SALE_UID cookie, which makes it easier for remote attackers to guess the cookie value and bypass authentication via a brute force attack.

Publicada: 30/5/2014, 14:55:08
Última modificación: 6/5/2026, 22:30:45

Referencias

InicioEventosBlogRecursosEquipo