Description
The web application uses Symfony framework. Symfony Profiler is enabled and accessible. It leads to disclosure of sensitive information about the web application.
Remediation
Disable the Profiler or restrict access to it
References
Related Vulnerabilities
WordPress Plugin S3Bubble Cloud Video With Adverts & Analytics Arbitrary File Download (0.7)
WebLogic Exposure of Sensitive Information to an Unauthorized Actor Vulnerability (CVE-2017-10334)
Joomla! Core 4.2.0 Information Disclosure (4.2.0)
WordPress Plugin VikBooking Hotel Booking Engine & PMS Multiple Vulnerabilities (1.5.3)