托管在 cadmos.eummena.io 的 Cadmos LTI 应用程序启用了 Laravel 调试模式(APP_DEBUG=true,APP_ENV=local),且该环境可被公开访问。未经身份验证的攻击者可以发送 GET 请求并触发未处理的异常,导致 Laravel 以明文形式暴露整个服务器环境信息,包括所有 .env 配置变量。该漏洞已于 2026-09-02 或之前修复。
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| Eummena | Cadmos LTI | < * |
affected |
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| Eummena | Cadmos LTI | 0 ~ * | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POCNo comments yet