CVE-2025-2376
CVSS 3.1 Score 7.3 of 10 (high)
Details
Published Mar 17, 2025
CWE ID 502
CWE ID 20
Summary
CVE-2025-2376 is a critical vulnerability affecting the viames Pair Framework, specifically the PHP Object Handler component and versions up to 1.9.11. The issue lies within the getCookieContent function in the /src/UserRemember.php file, which can be manipulated through the cookieName argument to trigger deserialization. This vulnerability can be exploited remotely, and the exploit has been made public, increasing the potential threat to affected systems.
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.
Affected Products
- Pair Framework