Asseco InfoMedica Plus Insufficient Access Control Vulnerability Allowing Password Retrieval and Privilege Escalation

Vulnerability

A vulnerability exists in Asseco InfoMedica Plus versions 4.0.0 prior to 4.50.1 and 5.0.0 prior to 5.38.0, allowing low privileged users to access encoded passwords of other accounts, including the main administrator. This issue arises from inadequate access control granularity. Additionally, passwords are stored in a recoverable format, enabling decoding by an attacker with access to these encoded passwords. The combined exploitation of this vulnerability with CVE-2025-8307 facilitates privilege escalation.

Impact

Exploitation of this vulnerability allows for unauthorized access to encoded passwords of all users, including administrators, which can be decoded and potentially used for privilege escalation.

Remediation

Users can upgrade to Asseco InfoMedica Plus versions 4.50.1 or 5.38.0 to address this vulnerability.

Added: Jan 8, 2026, 2:23 PM
Updated: Jan 8, 2026, 6:49 PM

Vulnerability Rating

Custom Algorithm
spread
0.0
impact
2.5
exploitability
5.2
remediation
7.7
relevance
1.8
threat
0.0
urgency
2.9
incentive
1.7

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.