Exposure of sensitive PHP information to an unauthorized control sphere in mautic/mautic images
Vulnerability Description
ImpactThis is an information disclosure vulnerability originating from PHP's base image. This vulnerability exposes the PHP version through an X-Powered-By header, which attackers could exploit to fingerprint the server and identify potential weaknesses. WorkaroundsThe mitigation requires changing the expose_php variable from "On" to "Off" in the file located at /usr/local/etc/php/php.ini.
Impact Analysis
Refer to official advisory for detailed impact metrics.
Remediation
Ensure systems are updated to the latest vendor-supplied patch levels.
Am I Vulnerable?
Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2025-7381
Credits & Attribution
The following person or organization is credited with identifying this vulnerability, as recorded in the NVD database:
- cibero42
- cibero42
- cibero42
More from mautic
View All →Affected Vendor
mautic
View all reports →