CWE-756
Missing Custom Error Page
BaseIncomplete
Description
The product does not return custom error pages to the user, possibly exposing sensitive information.
Hierarchy (View 1000)
CVEs mapped to this weakness (3)
| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2018-8913 | Hig | 0.46 | 7.1 | 0.01 | Apr 1, 2019 | Missing custom error page vulnerability in Synology Web Station before 2.1.3-0139 allows remote attackers to conduct phishing attacks via a crafted URL. | ||
| CVE-2023-27998 | Med | 0.34 | 5.3 | 0.00 | Sep 13, 2023 | A lack of custom error pages vulnerability [CWE-756] in FortiPresence versions 1.2.0 through 1.2.1 and all versions of 1.1 and 1.0 may allow an unauthenticated attacker with the ability to navigate to the login GUI to gain sensitive information via navigating to specific HTTP(s)… | ||
| CVE-2022-3175 | Med | 0.28 | 5.3 | 0.01 | Sep 13, 2022 | Missing Custom Error Page in GitHub repository ikus060/rdiffweb prior to 2.4.2. |
- risk 0.46cvss 7.1epss 0.01
Missing custom error page vulnerability in Synology Web Station before 2.1.3-0139 allows remote attackers to conduct phishing attacks via a crafted URL.
- risk 0.34cvss 5.3epss 0.00
A lack of custom error pages vulnerability [CWE-756] in FortiPresence versions 1.2.0 through 1.2.1 and all versions of 1.1 and 1.0 may allow an unauthenticated attacker with the ability to navigate to the login GUI to gain sensitive information via navigating to specific HTTP(s)…
- risk 0.28cvss 5.3epss 0.01
Missing Custom Error Page in GitHub repository ikus060/rdiffweb prior to 2.4.2.