CVE-2025-2376
Published:March 17, 2025
Updated:May 18, 2026
A vulnerability has been found in viames Pair Framework up to 1.9.11 and classified as critical. Affected by this vulnerability is the function getCookieContent of the file /src/UserRemember.php of the component PHP Object Handler. The manipulation of the argument cookieName leads to deserialization. The attack can be launched remotely. The exploit has been disclosed to the public and may be used.
Affected Packages
nexev-it/pair (PHP):
Affected version(s) =dev-master <1.0.0Fix Suggestion:
Update to version 1.0.0nexev-it/pair (PHP):
Affected version(s) >=1.7.0 <=1.8.3Fix Suggestion:
Update to version no_fixviames/pair (PHP):
Affected version(s) >=1.8.1 <1.8.4Fix Suggestion:
Update to version 1.8.4viames/pair (PHP):
Affected version(s) =dev-master <dev-pairFix Suggestion:
Update to version dev-pairviames/pair (PHP):
Affected version(s) >=1.8.16 <1.8.51Fix Suggestion:
Update to version 1.8.51viames/pair (PHP):
Affected version(s) >=1.7.0 <1.8Fix Suggestion:
Update to version 1.8viames/pair (PHP):
Affected version(s) =1.8.9 <1.8.10Fix Suggestion:
Update to version 1.8.10viames/pair (PHP):
Affected version(s) =dev-oauth2Fix Suggestion:
Update to version no_fixviames/pair (PHP):
Affected version(s) =1.8.7 <1.8.8Fix Suggestion:
Update to version 1.8.8viames/pair (PHP):
Affected version(s) =v1.x-dev <1.1.0Fix Suggestion:
Update to version 1.1.0viames/pair (PHP):
Affected version(s) =1.8.12 <1.8.13Fix Suggestion:
Update to version 1.8.13viames/pair (PHP):
Affected version(s) =dev-dev <dev-mainFix Suggestion:
Update to version dev-mainRelated Resources (4)
Do you need more information?
Contact UsCVSS v4
Base Score:
6.9
Attack Vector
NETWORK
Attack Complexity
LOW
Attack Requirements
NONE
Privileges Required
NONE
User Interaction
NONE
Vulnerable System Confidentiality
LOW
Vulnerable System Integrity
LOW
Vulnerable System Availability
LOW
Subsequent System Confidentiality
NONE
Subsequent System Integrity
NONE
Subsequent System Availability
NONE
CVSS v3
Base Score:
7.3
Attack Vector
NETWORK
Attack Complexity
LOW
Privileges Required
NONE
User Interaction
NONE
Scope
UNCHANGED
Confidentiality
LOW
Integrity
LOW
Availability
LOW
EPSS
Base Score:
0.20