CVE-2025-2376 | viames Pair Framework up to 1.9.11 PHP Object /src/UserRemember.php getCookieContent cookieName deserialization
A vulnerability has been found in viames Pair Framework up to 1.9.11 and classified as critical. Affected by this vulnerability is the function getCookieContent of the file /src/UserRemember.php of the component PHP Object Handler. The manipulation of the argument cookieName leads to deserialization.
This vulnerability is known as CVE-2025-2376. The attack can be launched remotely. Furthermore, there is an exploit available.