Description
The web application uses Laravel framework. Laravel LogViewer is enabled and accessible. In production environment, it leads to disclosure of sensitive information about the web application.
Remediation
Disable the LogViewer or restrict access to it
References
Related Vulnerabilities
Nonce Usage Detected in Content Security Policy (CSP) Directive
WordPress Plugin SSL Insecure Content Fixer Information Disclosure (2.0.0)
WordPress Plugin AccessAlly Information Disclosure (3.5.6)
WordPress Plugin Count per Day Information Disclosure (3.2.5)
PrestaShop Exposure of Sensitive Information to an Unauthorized Actor Vulnerability (CVE-2018-5682)