CVE-2025-1219

 

In PHP from 8.1.* before 8.1.32, from 8.2.* before 8.2.28, from 8.3.* before 8.3.19, from 8.4.* before 8.4.5, when requesting a HTTP resource using the DOM or SimpleXML extensions, the wrong content-type header is used to determine the charset when the requested resource performs a redirect. This may cause the resulting document to be parsed incorrectly or bypass validations.
https://nvd.nist.gov/vuln/detail/CVE-2025-1219

Categories

CWE-1116 : Inaccurate Comments
The source code contains comments that do not accuratelydescribe or explain aspects of the portion of the code with which the comment isassociated. Verify that each comment accurately reflects what is intended to happen during execution of the code.

References


 

CPE

cpe start end


REMEDIATION




EXPLOITS


Exploit-db.com

id description date
No known exploits

POC Github

Url
No known exploits

Other Nist (github, ...)

Url
No known exploits


CAPEC


Common Attack Pattern Enumerations and Classifications

id description severity
No entry