---
id: CVE-2025-61959
title: >-
  Prior to September 19, 2025, the Hospital Manager Backend Services returned
  verbose ASP.NET error pages for invalid WebResource.axd requests, disclosing
  framework and ASP.NET version information, stack traces, internal paths, and
  the ins…
summary: >-
  Prior to September 19, 2025, the Hospital Manager Backend Services returned
  verbose ASP.NET error pages for invalid WebResource.axd requests, disclosing
  framework and ASP.NET version information, stack traces, internal paths, and
  the ins…
severity: medium
cvss: 5.3
cvssVector: 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N'
cwe:
  - CWE-209
vendor: vertikalsystems
product: hospital_manager_backend_services
affected:
  - hospital_manager_backend_services <= 2025-09-19
published: '2025-10-29'
updated: '2026-10-08'
sourceUpdated: '2026-10-08T10:10:00.227'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2025-61959'
references:
  - url: 'https://www.cisa.gov/news-events/ics-medical-advisories/icsma-25-301-01'
    label: ics-cert@hq.dhs.gov
  - url: 'https://www.vertikalsystems.com/en/products/pm/contact.php'
    label: ics-cert@hq.dhs.gov
tags:
  - nvd
epss: 0.00273
epssPercentile: 0.18027
ingestedAt: '2026-10-08T10:28:17.265Z'
---

## Overview

Prior to September 19, 2025, the Hospital Manager Backend Services returned verbose ASP.NET error pages for invalid WebResource.axd requests, disclosing framework and ASP.NET version information, stack traces, internal paths, and the insecure configuration 'customErrors mode="Off"', which could have facilitated reconnaissance by unauthenticated attackers.

## Affected

- `hospital_manager_backend_services <= 2025-09-19`

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
