CVE-2025-9313
Severity CVSS v4.0:
CRITICAL
Type:
Unavailable / Other
Publication date:
28/10/2025
Last modified:
30/10/2025
Description
An unauthenticated user can connect to a publicly accessible database using arbitrary credentials. The system grants full access to the database by leveraging a previously authenticated connection through a "mmBackup" application. This flaw allows attackers to bypass authentication mechanisms and gain unauthorized access to database with sensitive data.<br />
<br />
This issue affects Asseco mMedica in versions before 11.9.5.
Impact
Base Score 4.0
9.30
Severity 4.0
CRITICAL



