Description
The web application uses Laravel framework. Laravel Health Monitor is enabled and accessible. In production environment, it leads to disclosure of sensitive information about the web application.
Remediation
Disable the Health Monitor or restrict access to it
References
Related Vulnerabilities
MediaWiki Exposure of Sensitive Information to an Unauthorized Actor Vulnerability (CVE-2014-9481)
Moodle Exposure of Sensitive Information to an Unauthorized Actor Vulnerability (CVE-2011-4304)
TCExam Exposure of Sensitive Information to an Unauthorized Actor Vulnerability (CVE-2021-20114)
Roundcube Exposure of Sensitive Information to an Unauthorized Actor Vulnerability (CVE-2015-5382)
WordPress Plugin WP SlackSync Information Disclosure (1.8.5)