CVE 5.9 MEDIUM

Recoverable passwords in Asseco Infomedica Plus_CVE-2025-8307

5.9 / 10
MEDIUM
CVSS:4.0/AV:L/AC:H/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N

Description

Asseco InfoMedica is a comprehensive solution used to manage both administrative and medical tasks in the healthcare sector. Passwords of all users are stored in a database in an encoded format. An attacker in possession of these encoded passwords is able to decode them by using an algorithm embedded in the client-side part of the software.ย 
This vulnerability has been fixed in versionsย 4.50.1 and 5.38.0

Basic Information

ID CVE-2025-8307
Source CERT-PL
Published Jan 8, 2026 at 13:43

Affected Product

Vendor Asseco
Product InfoMedica Plus
Version 5.0.0
Affected Versions Asseco InfoMedica Plus 5.0.0
Asseco InfoMedica Plus 4.0.0

CWE Classification

References

๐Ÿ’ญ Join the Security Discussion

๐Ÿ”’ Your email address will not be published. Required fields are marked *

โš ๏ธ Please be respectful and constructive in your comments. Security discussions should remain professional.