Metrics
Affected Vendors & Products
No advisories yet.
Solution
Vertikal Systems fixed these vulnerabilities by September 19, 2025. For more information, users should contact Vertikal Systems support https://www.vertikalsystems.com/en/products/pm/contact.php for assistance.
Workaround
No workaround given by the vendor.
Wed, 29 Oct 2025 22:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Prior to September 19, 2025, the Hospital Manager Backend Services returned verbose ASP.NET error pages for invalid WebResource.axd requests, disclosing framework and ASP.NET version information, stack traces, internal paths, and the insecure configuration 'customErrors mode="Off"', which could have facilitated reconnaissance by unauthenticated attackers. | |
| Title | Vertikal Systems Hospital Manager Backend Services Generation of Error Message Containing Sensitive Information | |
| Weaknesses | CWE-209 | |
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: icscert
Published:
Updated: 2025-10-29T21:54:51.533Z
Reserved: 2025-10-08T22:13:45.428Z
Link: CVE-2025-61959
No data.
Status : Received
Published: 2025-10-29T22:15:40.733
Modified: 2025-10-29T22:15:40.733
Link: CVE-2025-61959
No data.
OpenCVE Enrichment
No data.