CVE-2025-9313

An unauthenticated user can connect to a publicly accessible database using arbitrary credentials. The system grants full access to the database by leveraging a previously authenticated connection through a "mmBackup" application. This flaw allows attackers to bypass authentication mechanisms and gain unauthorized access to database with sensitive data. This issue affects Asseco mMedica in versions before 11.9.5.
CVSS

No CVSS.

Configurations

No configuration.

History

28 Oct 2025, 12:15

Type Values Removed Values Added
New CVE

Information

Published : 2025-10-28 12:15

Updated : 2025-10-30 15:05


NVD link : CVE-2025-9313

Mitre link : CVE-2025-9313

CVE.ORG link : CVE-2025-9313


JSON object : View

Products Affected

No product.

CWE
CWE-288

Authentication Bypass Using an Alternate Path or Channel