Description
The web application uses Laravel framework. Laravel Horizon is enabled and accessible. In production environment, it leads to disclosure of sensitive information about the web application.
Remediation
Disable the Horizon or restrict access to it
References
Related Vulnerabilities
WordPress Plugin iThemes Security (formerly Better WP Security) Multiple Vulnerabilities (3.6.3)
Unrestricted access to ImageResizer Diagnotics plugin
WordPress Plugin MasterStudy LMS-for Online Courses and Education Information Disclosure (3.2.10)
Undertow Exposure of Sensitive Information to an Unauthorized Actor Vulnerability (CVE-2020-1745)
WordPress Plugin Subscribe to Comments Unsubscribe Challenge Information Disclosure (2.0.2)