Home

Description

Due to webserver misconfiguration an unauthenticated remote attacker is able to read the source of php modules.

PUBLISHED Reserved 2025-04-16 | Published 2025-11-18 | Updated 2025-11-18 | Assigner CERTVDE




HIGH: 7.5CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N

Problem types

CWE-284 Improper Access Control

Product status

Default status
unaffected

0.0.0 (semver) before 2.2.0
affected

Default status
unaffected

0.0.0 (semver) before 2.2.0
affected

Default status
unaffected

0.0.0 (semver) before 2.2.0
affected

Credits

Noam Moshe from Claroty Team82 finder

Tomer Goldschmidt from Claroty Team82 finder

References

certvde.com/de/advisories/VDE-2025-097

cve.org (CVE-2025-41737)

nvd.nist.gov (CVE-2025-41737)

Download JSON