Detailed Error Messages Revealed
-
Hi, WordPress teams,
I have a question, my team found the issue regarding the “Detailed Error Messages Revealed”
the issue details like this:
The application displays detailed error messages when unhandled LDAP exceptions occur. Detailed technical error messages can allow an adversary to gain information about the application and database that could be used to conduct further attacks. The following expressions were matched in the HTTP response:- ((dn|dc|cn|ou|uid|o|c)=[\w\d]*,\s?){2,}
Here is the code from /wp-includes/js/tinymce/tinymce.min.js
function ry(u){var s,r,o=this,c=0,l=[],t=0,f=function(){return 0===t}
The question is, does this code have to be there? and related to LDAP? or is it just a coincidence that the variable name matches the regex I mentioned before?
Thanks
Viewing 6 replies - 1 through 6 (of 6 total)
Viewing 6 replies - 1 through 6 (of 6 total)
- The topic ‘Detailed Error Messages Revealed’ is closed to new replies.