Access Control Weakness in Asseco InfoMedica Affects Healthcare Administrators
CVE-2025-8306
5.1MEDIUM
What is CVE-2025-8306?
Asseco InfoMedica, a software solution for managing healthcare administrative and medical tasks, is affected by a vulnerability that allows low privileged users to access encoded passwords of all accounts, including that of the main administrator. This weakness arises from insufficient granularity in the access control mechanisms. Moreover, when exploited in conjunction with another vulnerability, it can enable an attacker to escalate their privileges. The issue has been resolved in versions 4.50.1 and 5.38.0.
Affected Version(s)
InfoMedica Plus 5.0.0 < 5.38.0
InfoMedica Plus 4.0.0 < 4.50.1
