Prior to September 19, 2025, the Hospital Manager Backend Services returned verbose ASP.NET error pages for invalid WebResource.axd requests, disclosing framework and ASP.NET version information, stack traces, internal paths, and the insecure configuration 'customErrors mode="Off"', which could have facilitated reconnaissance by unauthenticated attackers.
Metrics
Affected Vendors & Products
References
History
Thu, 30 Oct 2025 21:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Thu, 30 Oct 2025 14:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Vertikal Systems
Vertikal Systems hospital Manager Backend Services |
|
| Vendors & Products |
Vertikal Systems
Vertikal Systems hospital Manager Backend Services |
Wed, 29 Oct 2025 22:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Prior to September 19, 2025, the Hospital Manager Backend Services returned verbose ASP.NET error pages for invalid WebResource.axd requests, disclosing framework and ASP.NET version information, stack traces, internal paths, and the insecure configuration 'customErrors mode="Off"', which could have facilitated reconnaissance by unauthenticated attackers. | |
| Title | Vertikal Systems Hospital Manager Backend Services Generation of Error Message Containing Sensitive Information | |
| Weaknesses | CWE-209 | |
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: icscert
Published: 2025-10-29T21:54:51.533Z
Updated: 2025-10-30T20:32:15.522Z
Reserved: 2025-10-08T22:13:45.428Z
Link: CVE-2025-61959
Updated: 2025-10-30T20:32:09.621Z
Status : Awaiting Analysis
Published: 2025-10-29T22:15:40.733
Modified: 2025-10-30T15:03:13.440
Link: CVE-2025-61959
No data.
ReportizFlow