Symfony debugger is currently enabled on the following site : https://client.demenagements-gramme.be/
Visiting the debugger logs allows anyone to grab quotes URL.
This leads to potential customer information disclosure. ( eg https://client.spirouxdemenagements.be/mon-devis/ )
This also leads to LFI ( local file inclusion ) in the context of the Symfony app : https://client.demenagements-gramme.be/_profiler/open?file=config/services.yaml&line=0
Symfony debugger must be disabled in production environments as it keeps a log of every requests and exposes it to the public.
Symfony profiler enabled:
https://client.demenagements-gramme.be/_profiler/empty/search/results