# CVE-2025-8307

## Summary

- **CVE ID:** CVE-2025-8307
- **Severity:** MEDIUM
- **CVSS Score:** 5.9 (CVSS:4.0/AV:L/AC:H/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N)
- **CWE:** CWE-257
- **Published:** Jan 8, 2026
- **Last Modified:** Mar 12, 2026

## Description

Asseco InfoMedica is a comprehensive solution used to manage both administrative and medical tasks in the healthcare sector. Passwords of all users are stored in a database in an encoded format. An attacker in possession of these encoded passwords is able to decode them by using an algorithm embedded in the client-side part of the software. 
This vulnerability has been fixed in versions 4.50.1 and 5.38.0

## Affected Products

- Asseco — InfoMedica Plus (5.0.0)
- Asseco — InfoMedica Plus (4.0.0)

## References

- [CNA](https://cert.pl/en/posts/2026/01/CVE-2025-8306/)

## Exploitation Prediction (EPSS)

- **EPSS Score:** 0.12%
- **EPSS Percentile:** 2.1

---
_Exported from OnDuty AI Vulnerability Intelligence on 2026-09-10._