Логотип exploitDog
bind:CVE-2025-54459
Консоль
Логотип exploitDog

exploitDog

bind:CVE-2025-54459

Количество 2

Количество 2

nvd логотип

CVE-2025-54459

3 месяца назад

Prior to September 19, 2025, the Hospital Manager Backend Services exposed the ASP.NET tracing endpoint /trace.axd without authentication, allowing a remote attacker to obtain live request traces and sensitive information such as request metadata, session identifiers, authorization headers, server variables, and internal file paths.

CVSS3: 7.5
EPSS: Низкий
github логотип

GHSA-xcg5-r6rf-c8w7

3 месяца назад

Prior to September 19, 2025, the Hospital Manager Backend Services exposed the ASP.NET tracing endpoint /trace.axd without authentication, allowing a remote attacker to obtain live request traces and sensitive information such as request metadata, session identifiers, authorization headers, server variables, and internal file paths.

CVSS3: 7.5
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
nvd логотип
CVE-2025-54459

Prior to September 19, 2025, the Hospital Manager Backend Services exposed the ASP.NET tracing endpoint /trace.axd without authentication, allowing a remote attacker to obtain live request traces and sensitive information such as request metadata, session identifiers, authorization headers, server variables, and internal file paths.

CVSS3: 7.5
0%
Низкий
3 месяца назад
github логотип
GHSA-xcg5-r6rf-c8w7

Prior to September 19, 2025, the Hospital Manager Backend Services exposed the ASP.NET tracing endpoint /trace.axd without authentication, allowing a remote attacker to obtain live request traces and sensitive information such as request metadata, session identifiers, authorization headers, server variables, and internal file paths.

CVSS3: 7.5
0%
Низкий
3 месяца назад

Уязвимостей на страницу