PT-2025-7532 · Unknown · Harpia Diagsystem

Samuel Jesus

·

Published

2025-02-23

·

Updated

2025-02-23

·

CVE-2025-1575

CVSS v2.0

4.0

Medium

VectorAV:N/AC:L/Au:S/C:P/I:N/A:N
Name of the Vulnerable Software and Affected Versions Harpia DiagSystem version 12
Description A vulnerability has been found in Harpia DiagSystem. The issue affects an unknown function of the file /diagsystem/PACS/atualatendimento jpeg.php. The manipulation of the cod/codexame argument leads to improper control of resource identifiers. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used. The vendor was contacted early about this disclosure but did not respond in any way.
Recommendations As a temporary workaround, consider restricting access to the /diagsystem/PACS/atualatendimento jpeg.php file until a patch is available. Avoid using the cod/codexame argument in the affected file to minimize the risk of exploitation. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

Weakness Enumeration

Related Identifiers

CVE-2025-1575

Affected Products

Harpia Diagsystem