PT-2025-11474 · Unknown · Viames Pair Framework

Mcdruid

·

Published

2025-03-17

·

Updated

2025-03-22

·

CVE-2025-2376

CVSS v2.0

7.5

High

VectorAV:N/AC:L/Au:N/C:P/I:P/A:P
Name of the Vulnerable Software and Affected Versions viames Pair Framework versions 1.9.0 through 1.9.11
Description A critical vulnerability has been found in the viames Pair Framework, affecting the function getCookieContent of the file /src/UserRemember.php of the component PHP Object Handler. The manipulation of the argument cookieName leads to deserialization. The attack can be launched remotely. The exploit has been disclosed to the public and may be used.
Recommendations For versions 1.9.0 through 1.9.11, consider disabling the getCookieContent function as a temporary workaround until a patch is available. Restrict access to the vulnerable PHP Object Handler component to minimize the risk of exploitation. Avoid using the cookieName argument in the affected API endpoint until the issue is resolved. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

Deserialization of Untrusted Data

RCE

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2025-2376

Affected Products

Viames Pair Framework