diff --git a/submissions/description/sensitive_data_exposure/visible_detailed_error_page/full_path_disclosure/recommendations.md b/submissions/description/sensitive_data_exposure/visible_detailed_error_page/full_path_disclosure/recommendations.md index b9f67891..a88c371d 100644 --- a/submissions/description/sensitive_data_exposure/visible_detailed_error_page/full_path_disclosure/recommendations.md +++ b/submissions/description/sensitive_data_exposure/visible_detailed_error_page/full_path_disclosure/recommendations.md @@ -1,8 +1,6 @@ # Recommendation(s) -It is best practice to create a policy around what occurs when an error is made in the application, detailing what information is sent to the user and what information is logged. This policy should be circulated across all development teams so that their code adheres to the policy. - -When an error occurs the site should respond with a generic error message to the user that does not display internal details about the error or the underlying system. +When an error occurs the site should respond with a generic error message to the user that does not display internal details about the error, or the underlying system. It is recommended to create and implement a policy around what occurs when an error is made in the application. This should detail what information is sent to the user and what information is logged and be circulated across all development teams so that their code adheres to the policy. For more information refer to the following guides relating to this vulnerability: