The login page in Epiphany Cardio Server 3.3, 4.0, and 4.1 mishandles authentication requests, which allows remote attackers to conduct LDAP injection attacks, and consequently bypass intended access restrictions, via a crafted URL.
Name | Vendor | Start Version | End Version |
---|---|---|---|
Cardio_server | Ephiphanyheathdata | 3.3 (including) | 3.3 (including) |
Cardio_server | Ephiphanyheathdata | 4.0 (including) | 4.0 (including) |
Cardio_server | Ephiphanyheathdata | 4.1 (including) | 4.1 (including) |