Impact
The Cadmos LTI application at cadmos.eummena.io was running with Laravel’s debug mode enabled, exposing the entire server environment when an unhandled exception occurred. An unauthenticated attacker could send a simple GET request to any exposed endpoint, triggering the exception and receiving plaintext data including all .env configuration variables. This vulnerability allows attackers to obtain credentials, secret keys, and other sensitive data, resulting in a high‑severity confidentiality breach. The issue is formally classified as CWE-215 (Information Exposure Through Insecure Disclosure) and CWE-489 (Exposure of Sensitive Data Through Exception Handling).
Affected Systems
Eummena’s Cadmos LTI product, a Laravel framework application hosted publicly at cadmos.eummena.io, was affected. No specific application version is listed, so all instances of Cadmos LTI that were running with debug mode enabled in a publicly accessible environment are considered vulnerable.
Risk and Exploitability
The CVSS score of 9.2 places this flaw in the Critical range, indicating that exploitation offers significant impact. The EPSS score is not available, and the vulnerability is not listed in CISA’s KEV catalog. Because the application was publicly reachable and the vulnerability does not require any authentication or prior access, the likelihood of exploitation is high. An attacker can simply craft a web request to trigger the exception and harvest sensitive environment variables without any additional technical barriers.
OpenCVE Enrichment