This vulnerability has been fixed in versions 4.50.1 and 5.38.0
Project Subscriptions
No data.
No advisories yet.
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
| Link | Providers |
|---|---|
| https://cert.pl/en/posts/2026/01/CVE-2025-8306/ |
|
Thu, 08 Jan 2026 18:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Thu, 08 Jan 2026 14:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Asseco InfoMedica is a comprehensive solution used to manage both administrative and medical tasks in the healthcare sector. Passwords of all users are stored in a database in an encoded format. An attacker in possession of these encoded passwords is able to decode them by using an algorithm embedded in the client-side part of the software. This vulnerability has been fixed in versions 4.50.1 and 5.38.0 | |
| Title | Recoverable passwords in Asseco Infomedica Plus | |
| Weaknesses | CWE-257 | |
| References |
| |
| Metrics |
cvssV4_0
|
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: CERT-PL
Published:
Updated: 2026-01-08T14:18:51.530Z
Reserved: 2025-07-29T13:00:37.007Z
Link: CVE-2025-8307
Updated: 2026-01-08T14:18:49.302Z
Status : Awaiting Analysis
Published: 2026-01-08T14:15:56.873
Modified: 2026-01-08T18:08:18.457
Link: CVE-2025-8307
No data.
OpenCVE Enrichment
No data.