The login page in Epiphany Cardio Server 3.3, 4.0, and 4.1 mishandles authentication requests, which allows remote attackers to conduct LDAP injection attacks, and consequently bypass intended access restrictions, via a crafted URL.
Name | Vendor | Start Version | End Version |
---|---|---|---|
Cardio_server | Ephiphanyheathdata | 3.3 | 3.3 |
Cardio_server | Ephiphanyheathdata | 4.0 | 4.0 |
Cardio_server | Ephiphanyheathdata | 4.1 | 4.1 |