CVE-2025-1219

CVSS 3.1 Score 5.3 of 10 (medium)

Details

Published Mar 30, 2025
Updated: Apr 15, 2025
CWE ID 1116

Summary

CVE-2025-1219 is a vulnerability affecting various versions of PHP, including 8.1.* before 8.1.32, 8.2.* before 8.2.28, 8.3.* before 8.3.19, and 8.4.* before 8.4.5. This issue arises when using the DOM or SimpleXML extensions to request HTTP resources, which leads to the incorrect use of the content-type header for charset determination during a redirect. Consequently, the resulting document may be parsed incorrectly or validations may be bypassed.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share

Affected Products

  • PHP: Hypertext Preprocessor

Affected Vendors

  • Php