mautic/mautic
cpe:2.3:a:mautic:mautic:*:*:*:*:*:*:*
- < 6.0.3-20250707-apache
- < 6.0.3-20250707-fpm
- < 5.2.7-20250707-apache
- < 5.2.7-20250707-fpm
A moderate information disclosure vulnerability has been identified in Mautic Docker images, specifically in versions prior to 6.0.3-20250707-apache, 6.0.3-20250707-fpm, and 5.2.7-20250707-apache and fpm. This vulnerability arises from PHP's base image, which exposes the PHP version through an X-Powered-By header. Attackers could exploit this information to fingerprint the server and identify potential weaknesses.
Exploitation of this vulnerability allows for information disclosure, specifically the PHP version, which could be used to fingerprint the server and identify vulnerabilities.
To mitigate this vulnerability, change the 'expose_php' variable from 'On' to 'Off' in the php.ini file located at '/usr/local/etc/php/'.
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.