CVE-2025-9313
BaseFortify
Publication date: 2025-10-28
Last updated on: 2025-10-30
Assigner: CERT.PL
Description
Description
CVSS Scores
EPSS Scores
| Probability: | |
| Percentile: |
Meta Information
Affected Vendors & Products
| Vendor | Product | Version / Range |
|---|---|---|
| asseco | mmedica | * |
Helpful Resources
Exploitability
| CWE ID | Description |
|---|---|
| CWE-288 | The product requires authentication, but the product has an alternate path or channel that does not require authentication. |
Attack-Flow Graph
AI Powered Q&A
Can you explain this vulnerability to me?
This vulnerability allows an unauthenticated user to connect to a publicly accessible database using arbitrary credentials. The system mistakenly grants full access by leveraging a previously authenticated connection through the "mmBackup" application, enabling attackers to bypass authentication and gain unauthorized access to sensitive database data.
How can this vulnerability impact me? :
The vulnerability can lead to unauthorized access to sensitive data stored in the database, potentially resulting in data breaches, loss of confidentiality, and unauthorized data manipulation or theft.