Summary

Netsparker identified a database error message disclosure.

Impact
The error message may disclose sensitive information and this information can be used by an attacker to mount new attacks or to enlarge the attack surface. In rare conditions this may be a clue for an SQL injection vulnerability. Most of the time {PRODUCT} will detect and report that problem separately.
Remediation
Do not provide any error messages on production environments. Save error messages with a reference number to a backend storage such as a text file or database, then show this number and a static user-friendly error message to the user.
Classifications
PCI v3.1-6.5.5, PCI v3.2-6.5.5, CAPEC-118, WASC-13, OWASP 2013-A5 , CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:C/C:L/I:N/A:N