Information Disclosure Vulnerability in PILOS by THM Health
CVE-2025-62524
5.3MEDIUM
What is CVE-2025-62524?
PILOS, an interactive seminar platform built on BigBlueButton, has a vulnerability that exposes the PHP version in the X-Powered-By header, allowing potential attackers to fingerprint the server. This exposure can lead to the assessment of potential exploits against the web application. In addition, the displayed version of PILOS in the footer and accessible source code on GitHub provide further clues regarding the server’s PHP version. This flaw has been addressed in version 4.8.0 of PILOS.
Affected Version(s)
PILOS < 4.8.0
