Asseco InfoMedica is a comprehensive solution used to manage both administrative and medical tasks in the healthcare sector. Passwords of all users are stored in a database in an encoded format. An attacker in possession of these encoded passwords is able to decode them by using an algorithm embedded in the client-side part of the software.
This vulnerability has been fixed in versions 4.50.1 and 5.38.0
CVSS
No CVSS.
References
| Link | Resource |
|---|---|
| https://cert.pl/en/posts/2026/01/CVE-2025-8306/ |
Configurations
No configuration.
History
08 Jan 2026, 14:15
| Type | Values Removed | Values Added |
|---|---|---|
| New CVE |
Information
Published : 2026-01-08 14:15
Updated : 2026-01-08 18:08
NVD link : CVE-2025-8307
Mitre link : CVE-2025-8307
CVE.ORG link : CVE-2025-8307
JSON object : View
Products Affected
No product.
CWE
CWE-257
Storing Passwords in a Recoverable Format
