Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2025-54459

Опубликовано: 29 окт. 2025
Источник: nvd
CVSS3: 7.5
EPSS Низкий

Описание

Prior to September 19, 2025, the Hospital Manager Backend Services exposed the ASP.NET tracing endpoint /trace.axd without authentication, allowing a remote attacker to obtain live request traces and sensitive information such as request metadata, session identifiers, authorization headers, server variables, and internal file paths.

Ссылки

Уязвимые конфигурации

Конфигурация 1
cpe:2.3:a:vertikalsystems:hospital_manager_backend_services:*:*:*:*:*:*:*:*
Версия до 2025-09-19 (включая)

EPSS

Процентиль: 43%
0.00208
Низкий

7.5 High

CVSS3

Дефекты

CWE-497

Связанные уязвимости

CVSS3: 7.5
github
3 месяца назад

Prior to September 19, 2025, the Hospital Manager Backend Services exposed the ASP.NET tracing endpoint /trace.axd without authentication, allowing a remote attacker to obtain live request traces and sensitive information such as request metadata, session identifiers, authorization headers, server variables, and internal file paths.

EPSS

Процентиль: 43%
0.00208
Низкий

7.5 High

CVSS3

Дефекты

CWE-497