diff --git a/exposures/logs/laravel-telescope.yaml b/exposures/logs/laravel-telescope.yaml new file mode 100644 index 0000000000..1b07954008 --- /dev/null +++ b/exposures/logs/laravel-telescope.yaml @@ -0,0 +1,24 @@ +id: laravel-telescope + +info: + name: Laravel Telescope Disclosure + author: geeknik + description: Telescope provides insight into the requests coming into your application, exceptions, log entries, database queries, queued jobs, mail, notifications, cache operations, scheduled tasks, variable dumps, and more. + reference: https://laravel.com/docs/8.x/telescope + severity: medium + tags: laravel,disclosure,log + +requests: + - method: GET + path: + - "{{BaseURL}}/telescope/requests" + + redirects: true + matchers: + - type: word + words: + - "Telescope" + - "Requests" + - "Commands" + - "Schedule" + condition: and