This vulnerability has been fixed in versions 4.50.1 and 5.38.0
Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
No advisories yet.
| Link | Providers |
|---|---|
| https://cert.pl/en/posts/2026/01/CVE-2025-8306/ |
|
Thu, 08 Jan 2026 18:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Thu, 08 Jan 2026 14:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Asseco InfoMedica is a comprehensive solution used to manage both administrative and medical tasks in the healthcare sector. Passwords of all users are stored in a database in an encoded format. An attacker in possession of these encoded passwords is able to decode them by using an algorithm embedded in the client-side part of the software. This vulnerability has been fixed in versions 4.50.1 and 5.38.0 | |
| Title | Recoverable passwords in Asseco Infomedica Plus | |
| Weaknesses | CWE-257 | |
| References |
| |
| Metrics |
cvssV4_0
|
Subscriptions
No data.
Status: PUBLISHED
Assigner: CERT-PL
Published:
Updated: 2026-01-08T14:18:51.530Z
Reserved: 2025-07-29T13:00:37.007Z
Link: CVE-2025-8307
Updated: 2026-01-08T14:18:49.302Z
Status : Deferred
Published: 2026-01-08T14:15:56.873
Modified: 2026-04-15T00:35:42.020
Link: CVE-2025-8307
No data.
OpenCVE Enrichment
No data.