{"id":"CVE-2025-8307","title":"Asseco InfoMedica is a comprehensive solution used to manage both administrative and medical tasks in the healthcare sector","summary":"Asseco InfoMedica is a comprehensive solution used to manage both administrative and medical tasks in the healthcare sector. Passwords of all users are stored in a database in an encoded format. An attacker in possession of these encoded…","severity":"none","cwe":["CWE-257"],"published":"2026-01-08","updated":"2026-09-30","sourceUpdated":"2026-09-30T23:10:00.237","source":"NVD","sourceUrl":"https://nvd.nist.gov/vuln/detail/CVE-2025-8307","references":[{"url":"https://cert.pl/en/posts/2026/01/CVE-2025-8306/","label":"cvd@cert.pl"}],"tags":["nvd"],"epss":0.0012,"epssPercentile":0.01628,"ingestedAt":"2026-09-30T22:27:27.737Z","slug":"CVE-2025-8307","body":"## Overview\n\nAsseco InfoMedica is a comprehensive solution used to manage both administrative and medical tasks in the healthcare sector. Passwords of all users are stored in a database in an encoded format. An attacker in possession of these encoded passwords is able to decode them by using an algorithm embedded in the client-side part of the software. \nThis vulnerability has been fixed in versions 4.50.1 and 5.38.0\n\n## Remediation\n\nRefer to the linked advisories for vendor-supplied fixes and affected version ranges.","depth":"sunlit","depthScore":3,"depthScoreParts":{"impact":2.8,"likelihood":0,"exploitation":0,"ransomware":0},"changes":[]}