AUGUST 4, 2026
Live Feed
Back to database
Case File

CVE-2013-5350

HIGH · CVSS 7.5 EPSS 1.53%

Source: NVD + CISA KEV + EPSS (historical backfill) · Published 2014-01-24 · Last synced 2026-08-04

CyberRota Analysis

AI analysis pending.

CVE
CVE-2013-5350
Severity
HIGH
CVSS
7.5
EPSS
1.53%

Original NVD Description

The "Remember me" feature in the opSecurityUser::getRememberLoginCookie function in lib/user/opSecurityUser.class.php in OpenPNE 3.6.13 before 3.6.13.1 and 3.8.9 before 3.8.9.1 does not properly validate login data in HTTP Cookie headers, which allows remote attackers to conduct PHP object injection attacks, and execute arbitrary PHP code, via a crafted serialized object.