CVE-2025-7381
Severity CVSS v4.0:
Pending analysis
Type:
Unavailable / Other
Publication date:
09/07/2025
Last modified:
15/04/2026
Description
ImpactThis is an information disclosure vulnerability originating from PHP&#39;s base image. This vulnerability exposes the PHP version through an X-Powered-By header, which attackers could exploit to fingerprint the server and identify potential weaknesses.<br />
<br />
WorkaroundsThe mitigation requires changing the expose_php variable from "On" to "Off" in the file located at /usr/local/etc/php/php.ini.
Impact
Base Score 3.x
5.30
Severity 3.x
MEDIUM



