Improper Resource Handling in Harpia DiagSystem by Harpia
CVE-2025-1575
Key Information:
- Vendor
Harpia
- Status
- Vendor
- CVE Published:
- 23 February 2025
Badges
What is CVE-2025-1575?
A serious security vulnerability has been identified in Harpia DiagSystem 12 that allows an attacker to manipulate resource identifiers through the argument cod/codexame in the file /diagsystem/PACS/atualatendimento_jpeg.php. This improper control can expose the system to remote attacks, leading to unauthorized access and potential data breaches. The exploit is publicly known, and the vendor was notified but did not respond to the disclosure.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.
Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.
Affected Version(s)
DiagSystem 12
Exploit Proof of Concept (PoC)
PoC code is written by security researchers to demonstrate the vulnerability can be exploited. PoC code is also a key component for weaponization which could lead to ransomware.
References
CVSS V4
Timeline
- ๐ก
Public PoC available
- ๐พ
Exploit known to exist
Vulnerability published
Vulnerability Reserved
