Access Control Weakness in Asseco InfoMedica Affects Healthcare Administrators
CVE-2025-8306

5.1MEDIUM

Key Information:

Vendor

Asseco

Vendor
CVE Published:
8 January 2026

What is CVE-2025-8306?

Asseco InfoMedica, a software solution for managing healthcare administrative and medical tasks, is affected by a vulnerability that allows low privileged users to access encoded passwords of all accounts, including that of the main administrator. This weakness arises from insufficient granularity in the access control mechanisms. Moreover, when exploited in conjunction with another vulnerability, it can enable an attacker to escalate their privileges. The issue has been resolved in versions 4.50.1 and 5.38.0.

Affected Version(s)

InfoMedica Plus 5.0.0 < 5.38.0

InfoMedica Plus 4.0.0 < 4.50.1

References

CVSS V4

Score:
5.1
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
None
Availability:
None
Attack Vector:
Adjacent Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Maciej Kazulak
.