Direct naar de inhoud
⚡ Kritieke cyberalerts voor jouw sector & systemen — direct in je inbox. Aanmelden →
cybernieuws.nl Cybersecurity en informatiebeveiling nieuws alerts live · 5 min 135 bronnen 2 kritiek 19 vandaag
CVE's Videos Dagbriefing

← Terug naar CVE-database

CVE-2025-54459

HIGH · 7.5 CVSS Gepubliceerd: CWE-497

Beschrijving

Prior to September 19, 2025, the Hospital Manager Backend Services exposed the ASP.NET tracing endpoint /trace.axd without authentication, allowing a remote attacker to obtain live request traces and sensitive information such as request metadata, session identifiers, authorization headers, server variables, and internal file paths.

Vendors

Vertikalsystems

Affected products

Hospital Manager Backend Services

References