216.73.216.233

CVE-2025-48951

· Published 03/06/2025 21:15 · Modified 04/06/2025 21:15

Labels: CVE-2025-48951 2025-06-03CVE-2025-48951CWE-502[email protected]

Essential information

Published
03/06/2025 21:15
Modified
04/06/2025 21:15
Author
Creator
CVSS
9.3 CRITICAL (v3) 9.3 CRITICAL (v4.0)
CISA KEV
No
CWE
CVSS vector

CVSS metrics

Description

Auth0-PHP is a PHP SDK for Auth0 Authentication and Management APIs. Versions 8.0.0-BETA3 prior to 8.3.1 contain a vulnerability due to insecure deserialization of cookie data. If exploited, since SDKs process cookie content without prior authentication, a threat actor could send a specially crafted cookie containing malicious serialized data. Applications using the Auth0-PHP SDK are affected, as are applications using the Auth0/symfony, Auth0/laravel-auth0, or Auth0/wordpress SDKs, because those SDKsrely on the Auth0-PHP SDK versions from 8.0.0-BETA3 until 8.14.0. Version 8.3.1 contains a patch for the issue.

NVD status

Status
Awaiting Analysis — CVE has been recently published to the CVE List and has been received by the NVD.
Source
[email protected]
NVD
View on NVD

Affected products (CPE)

ProductCPE
auth0 / auth0-php cpe:2.3:a:auth0:auth0-php:8.0.0-BETA3-8.14.0:*:*:*:*:*:*:*
auth0 / auth0-symfony cpe:2.3:a:auth0:auth0-symfony:*:*:*:*:*:auth0_php:*:*
auth0 / auth0-laravel-auth0 cpe:2.3:a:auth0:auth0-laravel-auth0:*:*:*:*:*:auth0_php:*:*
auth0 / auth0-wordpress cpe:2.3:a:auth0:auth0-wordpress:*:*:*:*:*:auth0_php:*:*

References