← volver
CVE-2025-7381

Exposure of sensitive PHP information to an unauthorized control sphere in mautic/mautic images

CVSS 5.3 MEDIUMEPSS 0.2%CWE-497
ImpactThis is an information disclosure vulnerability originating from PHP's base image. This vulnerability exposes the PHP version through an X-Powered-By header, which attackers could exploit to fingerprint the server and identify potential weaknesses. WorkaroundsThe mitigation requires changing the expose_php variable from "On" to "Off" in the file located at /usr/local/etc/php/php.ini.
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
Productos afectados
mautic · Docker Mautic

¿Quieres saber si tu infraestructura está expuesta a esto?

Hablar con TrueHacking →