Description
The web application uses Laravel framework. Laravel Horizon is enabled and accessible. In production environment, it leads to disclosure of sensitive information about the web application.
Remediation
Disable the Horizon or restrict access to it
References
Related Vulnerabilities
WordPress Plugin Caldera Forms-More Than Contact Forms Information Disclosure (1.3.5.2)
Wildcard Detected in Port Portion of Content Security Policy (CSP) Directive
Vite Arbitrary File Read (CVE-2025-30208, CVE-2025-31125)
No Script Block Detected with the Hash Value Declared in Content Security Policy (CSP)
phpMyAdmin Exposure of Sensitive Information to an Unauthorized Actor Vulnerability (CVE-2016-9854)