Vertikal Systems Hospital Manager Backend Services got ICSMA-25-301-01. CVE-2025-54459 at 7.5, exposure of sensitive system information to an unauthorized control sphere, plus CVE-2025-61959, error messages that hand out sensitive information. Together they give an attacker unauthorized access to a hospital management backend and a tidy way to enumerate it through verbose errors. Pundhapat Sichamnong reported it.

Information disclosure of this kind rarely does harm on its own; its value is preparatory. A backend that reveals internal paths, component names or configuration to an unauthorized request hands an intruder the layout of a system they have not yet broken into, shortening the distance between a first probe and a focused attack. Verbose error messages make it worse by turning ordinary faults into a steady leak.

The weakness recurs because building software and running it want opposite things from an error. During development a detailed trace that names the failing component saves hours; on a system reachable over a network, that same detail is reconnaissance served on demand. Systems that never cleanly separate the two modes ship the developer's convenience straight to whoever sends a malformed request.

A hospital management backend sits behind the scheduling, records and administrative functions a facility runs on, so unauthorized reach into it exposes the connective tissue of operations rather than a single record. Combined with an easy way to enumerate the system through its own error output, a modestly rated disclosure becomes the opening move of a longer intrusion rather than a footnote.

Every stack trace and config detail returned to the client is a map for an attacker doing reconnaissance. Return generic errors to the user and keep the detail in your logs. The person triggering the exception is not always the person you want to help.