CVE-2013-7137: Burden Project Burden

Critical severity, CVSS 9.8. EPSS: 16.1% chance of exploitation in the next 30 days.

The "remember me" functionality in login.php in Burden before 1.8.1 allows remote attackers to bypass authentication and gain privileges by setting the burden_user_rememberme cookie to 1.

Affected products

Published 2014-01-26. Last modified 2026-06-17.