PT-2025-11344 · Php+11 · Php+11
Tim Düsterhus
·
Published
2025-01-01
·
Updated
2026-02-10
·
CVE-2025-1219
CVSS v4.0
6.3
Medium
| Vector | AV:N/AC:H/AT:P/PR:N/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N |
Name of the Vulnerable Software and Affected Versions
PHP versions 8.1.* through 8.1.31
PHP versions 8.2.* through 8.2.27
PHP versions 8.3.* through 8.3.18
PHP versions 8.4.* through 8.4.4
Description
The issue is related to the use of the wrong content-type header to determine the charset when a requested resource performs a redirect, potentially causing the resulting document to be parsed incorrectly or bypass validations. This can occur when requesting an HTTP resource using the DOM or SimpleXML extensions in PHP. The vulnerability may allow a remote attacker to redirect a user to an arbitrary URL.
Recommendations
Update PHP to version 8.1.32 or later for versions 8.1.*
Update PHP to version 8.2.28 or later for versions 8.2.*
Update PHP to version 8.3.19 or later for versions 8.3.*
Update PHP to version 8.4.5 or later for versions 8.4.*
Exploit
Fix
Open Redirect
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Alt Linux
Almalinux
Astra Linux
Centos
Debian
Linuxmint
Php
Red Hat
Red Os
Rocky Linux
Suse
Ubuntu