Issue name

Database connection string disclosed

Typical severity

Medium

Issue description

A database connection string specifies information about a data source and the means of connecting to it. In web applications, connection strings are generally used by the application tier to connect to the back database used for storing application data. They are usually read from server-side configuration files or hard-coded into application source code.

Issue remediation

It is almost never necessary for applications to disclose database connection strings to clients. The reason for the disclosure should be reviewed and addressed.

References

Vulnerability classifications

Web intro