cloudflare
tcp/443
GraphQL introspection is enabled.
This could leak to data leak if not properly configured.
Severity: medium
Fingerprint: c2db3a1c40d490db1a0bbaa32d2bb0d95373f0bbb804ac101e6fc4f58a1d442d
GraphQL introspection enabled at /graphql Types: 1019 (by kind: ENUM: 81, INPUT_OBJECT: 256, INTERFACE: 34, OBJECT: 638, SCALAR: 5, UNION: 5) Operations: - Query: Query | fields: MpRewardConfig, MpRewardIcon, MpRewardShoppingCartSpendingRules, NewestBlogPosts, RelatedBlogPosts - Mutation: Mutation | fields: AmxnotifStockSubscribe, MpRewardInvite, MpRewardRefer, MpRewardSpendingPoint, MpRewardSubscribe Directives: deprecated, include, oneOf, skip (total: 4)
Open service 188.114.97.3:443 · ba.qa24.gymbeam.dev
2026-01-09 01:06
HTTP/1.1 500 Internal Server Error
Date: Fri, 09 Jan 2026 01:06:44 GMT
Content-Type: text/html; charset=UTF-8
Transfer-Encoding: chunked
Connection: close
Server: cloudflare
Set-Cookie: PHPSESSID=4edb323415b0bbc8ecea32a30a6a866c; expires=Fri, 09 Jan 2026 21:06:44 GMT; Max-Age=72000; path=/; domain=ba.qa24.gymbeam.dev; secure; HttpOnly; SameSite=Lax
x-content-type-options: nosniff
x-xss-protection: 1; mode=block
x-frame-options: SAMEORIGIN
vary: Accept-Encoding
Report-To: {"group":"cf-nel","max_age":604800,"endpoints":[{"url":"https://a.nel.cloudflare.com/report/v4?s=SJczqtV%2BcftoZpvpKGBBCehiT4CUAhbPcyTE%2BLKhFyp5I6xOh9cFKOrjM6v69MqX2GsU%2FmMyhVrkdPJKRf7WXe31bZ99HcpDilafLgqye3G%2FNQ%3D%3D"}]}
x-varnish-status: MISS
pragma: no-cache
expires: -1
Cache-Control: no-store, no-cache, must-revalidate, max-age=0
via: 1.1 google
alt-svc: h3=":443"; ma=86400
cf-cache-status: DYNAMIC
Nel: {"report_to":"cf-nel","success_fraction":0.0,"max_age":604800}
Server-Timing: cfCacheStatus;desc="DYNAMIC"
Server-Timing: cfEdge;dur=10,cfOrigin;dur=7815
CF-RAY: 9bb008748e1eac70-YYZ
Open service 188.114.97.3:443 · ba.qa24.gymbeam.dev
2026-01-02 01:09
HTTP/1.1 500 Internal Server Error
Date: Fri, 02 Jan 2026 01:09:52 GMT
Content-Type: text/html; charset=UTF-8
Transfer-Encoding: chunked
Connection: close
Server: cloudflare
Set-Cookie: PHPSESSID=7ef7bd168cc5a5f95ec8c74a951ed0e9; expires=Fri, 02 Jan 2026 21:09:52 GMT; Max-Age=72000; path=/; domain=ba.qa24.gymbeam.dev; secure; HttpOnly; SameSite=Lax
x-content-type-options: nosniff
x-xss-protection: 1; mode=block
x-frame-options: SAMEORIGIN
vary: Accept-Encoding
Report-To: {"group":"cf-nel","max_age":604800,"endpoints":[{"url":"https://a.nel.cloudflare.com/report/v4?s=WQrWYPVGEFtcFqEYhwsmtUYZY7L%2F8XaJuw%2B0olYSCZ%2FCrmBK0TlEUoKeFVx0rYSyUXqx%2FMsRwpyT5dWej9B70LD4bycuAUo1VGyEVhShR7AqWA%3D%3D"}]}
x-varnish-status: MISS
pragma: no-cache
expires: -1
Cache-Control: no-store, no-cache, must-revalidate, max-age=0
via: 1.1 google
alt-svc: h3=":443"; ma=86400
cf-cache-status: DYNAMIC
Nel: {"report_to":"cf-nel","success_fraction":0.0,"max_age":604800}
Server-Timing: cfCacheStatus;desc="DYNAMIC"
Server-Timing: cfEdge;dur=12,cfOrigin;dur=9789
CF-RAY: 9b765f5f9fae39f8-YYZ
Open service 188.114.97.3:443 · ba.qa24.gymbeam.dev
2025-12-22 09:25
HTTP/1.1 200 OK Date: Mon, 22 Dec 2025 09:25:33 GMT Content-Type: text/html; charset=UTF-8 Transfer-Encoding: chunked Connection: close Server: cloudflare Set-Cookie: PHPSESSID=046ad3a69a59d9c44dc585ae255aeda0; expires=Tue, 23 Dec 2025 05:25:33 GMT; Max-Age=72000; path=/; domain=ba.qa24.gymbeam.dev; secure; HttpOnly; SameSite=Lax