Laravel Environment Configuration File Detected

Severity: Low
Summary#

Invicti detected a Laravel environment configuration file (.env) on your web server.

Impact#
Depending on the nature of the connection string disclosed, an attacker can mount one or more of the following types of attacks:
  • Access the database or other data resources. With the privileges of the account obtained; attempt to read, update or delete arbitrary data from the database.
  • Access password protected administrative mechanisms such as "dashboard", "management console" and "admin panel" potentially leading to full control of the application.
Actions To Take#

Restrict access to this file on the web server.

Further Reading#

Build your resistance to threats. And save hundreds of hours each month.

Get a demo See how it works