Description
Due to incorrect configuration, the web application discloses a full path to a file with source code, which generated a response, in the "X-SourceFiles" header.
Remediation
Hide X-SourceFiles header
References
Related Vulnerabilities
WordPress Plugin WP-RecentComments Information Disclosure (2.2.7)
WordPress 3.9.x Multiple Vulnerabilities (3.9 - 3.9.37)
Joomla! Core improper access check in webservice endpoints
WordPress Plugin All-in-One WP Migration Information Disclosure (7.0)
WordPress Plugin Share Drafts Publicly Information Disclosure (1.1.4)