mediDOK Remote Code Execution Vulnerability via Untrusted Data Deserialization

Vulnerability

A remote code execution vulnerability exists in mediDOK versions prior to 2.5.18.43. This issue arises from the deserialization of untrusted data, allowing remote attackers to execute arbitrary code on the target system.

Impact

Exploitation of this vulnerability allows for authenticated remote code execution on the server where mediDOK is installed.

Remediation

Users are advised to update to mediDOK version 2.5.18.43, which addresses this vulnerability. Instructions for updating can be found on the mediDOK website.

Added: Jun 9, 2025, 7:46 PM
Updated: Jun 9, 2025, 7:46 PM

Vulnerability Rating

Custom Algorithm
spread
0.0
impact
10.0
exploitability
7.4
remediation
7.7
relevance
0.0
threat
0.0
urgency
2.9
incentive
5.8

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.