Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-xcg5-r6rf-c8w7

Опубликовано: 30 окт. 2025
Источник: github
Github: Не прошло ревью
CVSS4: 8.7
CVSS3: 7.5

Описание

Prior to September 19, 2025, the Hospital Manager Backend Services exposed the ASP.NET tracing endpoint /trace.axd without authentication, allowing a remote attacker to obtain live request traces and sensitive information such as request metadata, session identifiers, authorization headers, server variables, and internal file paths.

Prior to September 19, 2025, the Hospital Manager Backend Services exposed the ASP.NET tracing endpoint /trace.axd without authentication, allowing a remote attacker to obtain live request traces and sensitive information such as request metadata, session identifiers, authorization headers, server variables, and internal file paths.

EPSS

Процентиль: 43%
0.00208
Низкий

8.7 High

CVSS4

7.5 High

CVSS3

Дефекты

CWE-497

Связанные уязвимости

CVSS3: 7.5
nvd
3 месяца назад

Prior to September 19, 2025, the Hospital Manager Backend Services exposed the ASP.NET tracing endpoint /trace.axd without authentication, allowing a remote attacker to obtain live request traces and sensitive information such as request metadata, session identifiers, authorization headers, server variables, and internal file paths.

EPSS

Процентиль: 43%
0.00208
Низкий

8.7 High

CVSS4

7.5 High

CVSS3

Дефекты

CWE-497