CWE-540

Inclusion of Sensitive Information in Source Code

Medium

Description

Source code on a web server or repository often contains sensitive information and should generally not be accessible to users.

Potential Impact

How to Fix

Architecture and Design

Recommendations include removing this script from the web server and moving it to a location not accessible from the Internet.

Detection Methods

Related Weaknesses

References

View on MITRE CWE Database →

Need Help Fixing This Vulnerability?

Our security experts can help you identify and remediate CWE-540 vulnerabilities in your codebase.

Get Security Assessment