Description
The __VIEWSTATE parameter is not encrypted for one or more pages. To reduce the chance of someone intercepting the information stored in the ViewState, it is good design to encrypt the ViewState.
Remediation
Turn on the encryption mode for the view state. Consult web references for more information, taking into consideration ASP.NET version
References
Related Vulnerabilities
WordPress Plugin Yoast SEO Information Disclosure (3.2.4)
PostgreSQL Exposure of Sensitive Information to an Unauthorized Actor Vulnerability (CVE-2015-5288)
WordPress Plugin Contact Form Email Information Disclosure (1.2.66)
Apache Tomcat version older than 4.1.37
WordPress Plugin SSL Insecure Content Fixer Information Disclosure (2.0.0)