Prior to September 19, 2025, the Hospital Manager Backend Services returned verbose ASP.NET error pages for invalid WebResource.axd requests, disclosing framework and ASP.NET version information, stack traces, internal paths, and the insecure configuration 'customErrors mode="Off"', which could have facilitated reconnaissance by unauthenticated attackers.
References
| Link | Resource |
|---|---|
| https://www.cisa.gov/news-events/ics-medical-advisories/icsma-25-301-01 | Mitigation Third Party Advisory US Government Resource |
| https://www.vertikalsystems.com/en/products/pm/contact.php | Product |
Configurations
History
No history.
Information
Published : 2025-10-29 22:15
Updated : 2025-11-06 19:20
NVD link : CVE-2025-61959
Mitre link : CVE-2025-61959
CVE.ORG link : CVE-2025-61959
JSON object : View
Products Affected
vertikalsystems
- hospital_manager_backend_services
CWE
CWE-209
Generation of Error Message Containing Sensitive Information
