Information Disclosure Vulnerability in PILOS by THM Health
CVE-2025-62524

5.3MEDIUM

Key Information:

Vendor

Thm-health

Status
Vendor
CVE Published:
27 October 2025

What is CVE-2025-62524?

PILOS, an interactive seminar platform built on BigBlueButton, has a vulnerability that exposes the PHP version in the X-Powered-By header, allowing potential attackers to fingerprint the server. This exposure can lead to the assessment of potential exploits against the web application. In addition, the displayed version of PILOS in the footer and accessible source code on GitHub provide further clues regarding the server’s PHP version. This flaw has been addressed in version 4.8.0 of PILOS.

Affected Version(s)

PILOS < 4.8.0

References

CVSS V3.1

Score:
5.3
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
None
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.