Summary

Acunetix 360 identified a username disclosure (MySQL) in the error message.

Impact

An attacker can perform brute-force or dictionary-based password guessing on the disclosed username. It may also help the attacker identify other vulnerabilities or further their exploitation of other identified vulnerabilities.

Remediation

  • Error messages should be disabled.
  • Remove this kind of sensitive data from the output.

Severity

Low

Classification

PCI v3.2-6.5.5 CAPEC-118 CWE-201 HIPAA-164.306(a) ISO27001-A.18.1.4 WASC-13 OWASP 2013-A5 OWASP 2017-A3