Database Access Vulnerability in Asseco mMedica Software
CVE-2025-9313
9.3CRITICAL
What is CVE-2025-9313?
An unauthenticated user can exploit a flaw in Asseco mMedica software to connect to a publicly accessible database using arbitrary credentials. This vulnerability arises from a misconfigured authentication mechanism within the 'mmBackup' application, enabling malicious users to bypass standard security protocols. By leveraging this issue, attackers are granted full access to the database, potentially exposing sensitive information and putting data integrity at risk.
Affected Version(s)
mMedica 0 < 11.9.5
