Home
MEDIUM: 5.3 CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:NDefault status
unaffected
Any version before 6.09.01.62
affected
Description
Asseco ADMX system is used for processing medical records. It allows logged in users to access medical files belonging to other users through manipulation of GET arguments containing document IDs. This issue has been fixed in 6.09.01.62 version of ADMX.
Problem types
CWE-639 Authorization Bypass Through User-Controlled Key
Product status
Any version before 6.09.01.62
Credits
Wiktor Mróz
References
cert.pl/en/posts/2026/01/CVE-2025-4596