longwave
longwave copied to clipboard
[Bug] Missing error handling / no code exposing in case of errors
In case of intentional errors in the call, an error message shall be displayed without publishing the code. In this case, it is not critical due to open source, but exposing the code may give potential attackers further clues to vulnerabilities.
Sample: https://localhost:3000/jdsfh%20jkdsahf%20jkdshg%20fdklg%20hfkdlg%20hdfsjlgh.%20hgfdh%20gfh