CVE 6.9 MEDIUM

Vertikal Systems Hospital Manager Backend Services Generation of Error Message Containing Sensitive Information_CVE-2025-61959

6.9 / 10
MEDIUM
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N

Description

Prior to September 19, 2025, the Hospital Manager Backend Services returned verbose ASP.NET error pages for invalid WebResource.axd requests, disclosing framework and ASP.NET version information, stack traces, internal paths, and the insecure configuration 'customErrors mode="Off"', which could have facilitated reconnaissance by unauthenticated attackers.

Basic Information

ID CVE-2025-61959
Source icscert
Published Oct 29, 2025 at 21:54

Affected Product

Vendor Vertikal Systems
Product Hospital Manager Backend Services
Affected Versions Vertikal Systems Hospital Manager Backend Services 0

CWE Classification

References

💭 Join the Security Discussion

🔒 Your email address will not be published. Required fields are marked *

⚠️ Please be respectful and constructive in your comments. Security discussions should remain professional.