Description
Exposing PHP errors, stack details, or database error messages to users in production can reveal internal structure and sensitive information.
Potential impact
Paths, queries, account names, and implementation details may help an attacker plan further attacks.
Remediation
Disable display_errors in production and record detailed errors only in server-side logs.
Examples
Before
php
<?php
ini_set('display_errors', '1');
echo mysqli_error($db);
After
php
<?php
ini_set('display_errors', '0');
error_log($e->getMessage());
Explanation:
- Before: Debugging or error details are exposed to users.
- After: Error display is disabled and the error details are written to the server log.
Restrict log access and remove or redact secrets such as credentials.