Intel

AIKIDO-2025-10419

googleads/google-ads-php is vulnerable to Exposure of Sensitive Information

Exposure of Sensitive Information Pre-CVE
Found by Aikido Intel before public disclosure or CVE publication.
Published Jun 30, 2025

48

Medium Risk

This Affects:

PHPgoogleads/google-ads-php
6.1.0 - 28.0.0
Fixed in 29.0.0
Are you affected? Scan for Free

TL;DR

Affected versions of this package may expose sensitive information by invoking the phpinfo(INFO_GENERAL) function. This can reveal environment details such as PHP version and configuration, which could aid attackers in crafting targeted exploits.

Who does this affect?

You are affected if you are using a version which is within vulnerability ranges

Background info

googleads/google-ads-php is vulnerable to Exposure of Sensitive Information in versions 6.1.0 - 28.0.0.

How to fix this

Upgrade the googleads/google-ads-php library to a patch version.