CVE Wiki Pixee · CVE intelligence
← All CVEs

CVE-2025-34292

Critical · CVSS 9.4

Rox (BeWelcome) — PHP object injection via deserialization of untrusted data (RCE / arbitrary file write)

CVSS
9.4
nvd
EPSS
KEV
No
Class
oss containerizable
CWE-502

Description

Rox, the software running BeWelcome, contains a PHP object injection vulnerability resulting from deserialization of untrusted data. User-controlled input is passed to PHP's unserialize(): the POST parameter `formkit_memory_recovery` in \\RoxPostHandler::getCallbackAction and the 'memory cookie' read by \\RoxModelBase::getMemoryCookie (bwRemember). (1) If present, `formkit_memory_recovery` is processed and passed to unserialize(), and (2) restore-from-memory functionality calls unserialize() on the bwRemember cookie value. Gadget chains present in Rox and bundled libraries enable exploitation of object injection to write arbitrary files or achieve remote code execution. Successful exploitation can lead to full site compromise. This vulnerability was remediated with commit c60bf04 (2025-06-16).

Search profile — drives PoC discovery

Symbols RoxPostHandler::getCallbackActionRoxModelBase::getMemoryCookieformkit_memory_recoverybwRememberunserialize
Keywords CVE-2025-34292BeWelcomeRox PHP object injectionPHP deserialization RCEformkit_memory_recovery unserializebwRemember cookie deserializationCWE-502 BeWelcomegadget chain Roxc60bf04
Versions: Prior to commit c60bf04 (2025-06-16)

References

Status: enriched · ingested 2026-07-15T00:00:20.000Z · profiled 2026-07-15T00:30:20.000Z