CVE-2025-9313

Severity CVSS v4.0:
CRITICAL
Type:
Unavailable / Other
Publication date:
28/10/2025
Last modified:
30/10/2025

Description

An unauthenticated user can connect to a publicly accessible database using arbitrary credentials. The system grants full access to the database by leveraging a previously authenticated connection through a "mmBackup" application. This flaw allows attackers to bypass authentication mechanisms and gain unauthorized access to database with sensitive data.<br /> <br /> This issue affects Asseco mMedica in versions before 11.9.5.