Description
The web application uses Laravel framework. Laravel Horizon is enabled and accessible. In production environment, it leads to disclosure of sensitive information about the web application.
Remediation
Disable the Horizon or restrict access to it
References
Related Vulnerabilities
WordPress Plugin Fast Velocity Minify Information Disclosure (2.7.6)
Plone CMS Exposure of Sensitive Information to an Unauthorized Actor Vulnerability (CVE-2012-5497)
Unsafe value for session tracking in WEB-INF/web.xml
WordPress Plugin Login by Auth0 Multiple Vulnerabilities (3.11.3)
WebLogic Exposure of Sensitive Information to an Unauthorized Actor Vulnerability (CVE-2021-40690)