Error messages can be configured by the user (post authentication)
Hello,
I would like to ask if there is something like the parameter "Suppress SQL Error = 1 " into the file psappsrv.cfg to Enabling SQL Error Message Suppression, to not give detail information or not present the message "Invalid URL -unknown Content Type or not Content Type found in URL https://psalfauat/c2544/EMPLOYEE/ERP/YouWonAnIpad" when the end-user type an invalid URL (post authentication)
We have the vulnerability report: Error messages on the site can be controlled by the user. A message such as the following can cause a legitimate user to send his credentials to a malicious site.
So we would like to know if is possible to eliminated the detail massage when a not valid URL is typing by the end-user