Description
In the development mode Grails provides a database console (available at /dbconsole/). This database console should not be available in the production environment as it leaks sensitive information about the database structure and permits executing SQL queries.
Remediation
It's recommended to restrict access to the database console by running Grails in production mode.
References
Related Vulnerabilities
Case-Insensitive Routing Bypass in Express.js Application
WordPress Plugin Transposh WordPress Translation Multiple Vulnerabilities (1.0.8.1)
Node.js Running in Development Mode
WordPress Plugin Count per Day Information Disclosure (3.2.5)
WordPress Plugin Backup & Restore Dropbox Multiple Vulnerabilities (1.4.7.5)