CVE-2025-7381
Last modified
CVE-2025-7381 is a medium-severity vulnerability rated 5.3/10 on the CVSS scale. ImpactThis is an information disclosure vulnerability originating from PHP's base image. This vulnerability exposes the PHP version through an X-Powered-By header, which attackers could exploit to fingerprint the server and identify potential weaknesses. WorkaroundsThe mitigation requires changing the expose_php variable from "On" to "Off" in the file located at /usr/local/etc/php/php.ini.. EPSS estimates a 0.24% chance of exploitation in the next 30 days.
Description
ImpactThis is an information disclosure vulnerability originating from PHP's base image. This vulnerability exposes the PHP version through an X-Powered-By header, which attackers could exploit to fingerprint the server and identify potential weaknesses. WorkaroundsThe mitigation requires changing the expose_php variable from "On" to "Off" in the file located at /usr/local/etc/php/php.ini.
Metrics
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
Weakness Enumeration
References
Timeline
- Published
- Last Modified
- Status
- Deferred
Frequently Asked Questions
What is CVE-2025-7381?
How severe is CVE-2025-7381?
How do I fix CVE-2025-7381?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2025
- CVE-2025-7374The WP JobHunt plugin for WordPress, used by the JobCareer t…5.4
- CVE-2025-7375A denial-of-service (DoS) vulnerability was identified in Om…6.5
- CVE-2025-7376Windows Shortcut Following (.LNK) vulnerability in multiple …5.9
- CVE-2025-7378An improper Input Validation vulnerability allows injecting …6
- CVE-2025-7379A security bypass vulnerability allows exploitation via Reve…5.2
- CVE-2025-7380A stored Cross-Site Scripting (XSS) vulnerability exists in …4.8
- CVE-2025-7382A command injection vulnerability in WebAdmin of Sophos Fire…8.8
- CVE-2025-7383Padding oracle attack vulnerability in Oberon microsystem AG…5.9
- CVE-2025-7384The Database for Contact Form 7, WPforms, Elementor forms pl…9.8
- CVE-2025-7385Input from search query parameter in GOV CMS is not sanitize…9.3
- CVE-2025-7386Information exposure vulnerability in Hitachi Storage Naviga…6.8
- CVE-2025-7387The Lana Downloads Manager plugin for WordPress is vulnerabl…5.5
Are you affected by CVE-2025-7381?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
