Error-information disclosure

Error-information disclosure

Description

Exposing PHP errors, stack details, or database error messages to users in production can reveal internal structure and sensitive information.

Potential impact

Paths, queries, account names, and implementation details may help an attacker plan further attacks.

Remediation

Disable display_errors in production and record detailed errors only in server-side logs.

Examples

Before

php
<?php
ini_set('display_errors', '1');
echo mysqli_error($db);

After

php
<?php
ini_set('display_errors', '0');
error_log($e->getMessage());

Explanation:

  • Before: Debugging or error details are exposed to users.
  • After: Error display is disabled and the error details are written to the server log.

Restrict log access and remove or redact secrets such as credentials.

References