CVE-2013-5350

high
Published 2014-01-24 · Modified 2026-04-29
CVSS v3
CVSS v2
7.5
VIR risk
7.5

Description

The "Remember me" feature in the opSecurityUser::getRememberLoginCookie function in lib/user/opSecurityUser.class.php in OpenPNE 3.6.13 before 3.6.13.1 and 3.8.9 before 3.8.9.1 does not properly validate login data in HTTP Cookie headers, which allows remote attackers to conduct PHP object injection attacks, and execute arbitrary PHP code, via a crafted serialized object.

Predictions

Exploit likelihood
20%
Patch ETA

Heuristic predictions, AS-IS, for prioritization only.

Mitigations

vendor Authored 2026-05-27

Vendor advisory: PSIRT-CNA@flexerasoftware.com — https://www.openpne.jp/archives/12293/

vendor Authored 2026-05-27

Vendor advisory: PSIRT-CNA@flexerasoftware.com — http://secunia.com/secunia_research/2014-1/

vendor Authored 2026-05-27

Vendor advisory: PSIRT-CNA@flexerasoftware.com — http://secunia.com/advisories/54043

Application impact

VendorProductVersionsFixed
tejimayaopenpne3.6.13
tejimayaopenpne3.8.9

References

CWEs

CWE-20

Verify integrity in audit chain (admin only). AS-IS.