CVE-2025-61959

MEDIUM

Vertikalsystems Hospital Manager Back... - Error Information Exposure

Title source: rule
STIX 2.1

Description

Prior to September 19, 2025, the Hospital Manager Backend Services returned verbose ASP.NET error pages for invalid WebResource.axd requests, disclosing framework and ASP.NET version information, stack traces, internal paths, and the insecure configuration 'customErrors mode="Off"', which could have facilitated reconnaissance by unauthenticated attackers.

Scores

CVSS v3 5.3
EPSS 0.0004
EPSS Percentile 12.5%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact partial

Details

CWE
CWE-209
Status published
Products (1)
vertikalsystems/hospital_manager_backend_services < 2025-09-19
Published Oct 29, 2025
Tracked Since Feb 18, 2026