CWE-756Base

Missing Custom Error Page

Incomplete in the CWE catalog · 3 CVEs mapped

3
CVEs mapped
5.3
Median CVSS
What it is

The product does not return custom error pages to the user, possibly exposing sensitive information.

Recent examples
5.3cvss
CVE-2023-27998

A lack of custom error pages vulnerability [CWE-756] in FortiPresence versions 1.2.0 through 1.2.1 and all versions of 1.1 and 1.0 may allow an unauthenticated…

A lack of custom error pages vulnerability [CWE-756] in FortiPresence versions 1.2.0 through 1.2.1 and all versions of 1.1 and 1.0 may allow an unauthenticated attacker with the ability to navigate to the login GUI to gain sensitive information via navigating to specific HTTP(s) paths.

MEDIUMno explanation yet
0%
epss
5.3cvss
CVE-2022-3175

Missing Custom Error Page in ikus060/rdiffweb

Missing Custom Error Page in GitHub repository ikus060/rdiffweb prior to 2.4.2.

MEDIUMno explanation yet
1%
epss
7.1cvss
CVE-2018-8913

Missing custom error page vulnerability in Synology Web Station before 2.1.3-0139 allows remote attackers to conduct phishing attacks via a crafted URL

Missing custom error page vulnerability in Synology Web Station before 2.1.3-0139 allows remote attackers to conduct phishing attacks via a crafted URL.

HIGHno explanation yet
1%
epss
The record
Technical detail
CWE ID
CWE-756
Abstraction
Base
Structure
Simple
Status
Incomplete