QID 150820
Date Published: 2024-03-07
QID 150820: Disclosure of Comments in HTML Source
During scan of the web site, comments were detected in HTML response. The content in comments may lead to sensitive information leakage due information about software versions, database names and more.
Information in comments can lead to information leakage related to web application. The information can result in potential use of data by attackers to exploit the application. The exploits can include SQLI, RCE, LFI etc.
Solution
Comments in HTML response should be removed to avoid sensitive information exposure. Review the web application HTML source and remove all text between tags: <!-- and -->, tags included.
Vendor References
CVEs related to QID 150820
Software Advisories
| Advisory ID | Software | Component | Link |
|---|