CVE-2025-54459

Prior to September 19, 2025, the Hospital Manager Backend Services exposed the ASP.NET tracing endpoint /trace.axd without authentication, allowing a remote attacker to obtain live request traces and sensitive information such as request metadata, session identifiers, authorization headers, server variables, and internal file paths.
Configurations

No configuration.

History

29 Oct 2025, 22:15

Type Values Removed Values Added
New CVE

Information

Published : 2025-10-29 22:15

Updated : 2025-10-30 15:03


NVD link : CVE-2025-54459

Mitre link : CVE-2025-54459

CVE.ORG link : CVE-2025-54459


JSON object : View

Products Affected

No product.

CWE
CWE-497

Exposure of Sensitive System Information to an Unauthorized Control Sphere