Description
The web application uses Laravel framework. Laravel LogViewer is enabled and accessible. In production environment, it leads to disclosure of sensitive information about the web application.
Remediation
Disable the LogViewer or restrict access to it
References
Related Vulnerabilities
JavaMelody publicly accessible
WordPress Plugin HB AUDIO GALLERY LITE Arbitrary File Download (1.0.0)
XWiki Exposure of Sensitive Information to an Unauthorized Actor Vulnerability (CVE-2023-29517)
The POODLE attack (SSLv3 with CBC cipher suites)
Cookies with missing, inconsistent or contradictory properties