---
id: CVE-2025-62524
title: >-
  PILOS (Platform for Interactive Live-Online Seminars) is a frontend for
  BigBlueButton
summary: >-
  PILOS (Platform for Interactive Live-Online Seminars) is a frontend for
  BigBlueButton. PILOS before 4.8.0 exposes the PHP version via the X-Powered-By
  header, enabling attackers to fingerprint the server and assess potential
  exploits. Th…
severity: medium
cvss: 5.3
cvssVector: 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N'
cwe:
  - CWE-200
  - CWE-497
vendor: thm
product: pilos
affected:
  - pilos < 4.8.0
patched:
  - pilos 4.8.0
published: '2025-10-27'
updated: '2026-10-08'
sourceUpdated: '2026-10-08T11:10:00.250'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2025-62524'
references:
  - url: >-
      https://github.com/THM-Health/PILOS/commit/14655bc4f8128ffd2b3c25004b01d9a802808da8
    label: security-advisories@github.com
  - url: >-
      https://github.com/THM-Health/PILOS/security/advisories/GHSA-q93h-5j6h-j22x
    label: security-advisories@github.com
tags:
  - nvd
epss: 0.00261
epssPercentile: 0.16406
ingestedAt: '2026-10-08T11:31:27.649Z'
---

## Overview

PILOS (Platform for Interactive Live-Online Seminars) is a frontend for BigBlueButton. PILOS before 4.8.0 exposes the PHP version via the X-Powered-By header, enabling attackers to fingerprint the server and assess potential exploits. This information disclosure vulnerability originates from PHP’s base image. Additionally, the PHP version can also be inferred through the PILOS version displayed in the footer and by examining the source code available on GitHub. This information disclosure vulnerability has been patched in PILOS in v4.8.0.

## Affected

- `pilos < 4.8.0`

## Remediation

Upgrade past the affected range:

- `pilos 4.8.0`
