Epiphany · Epiphany Cardio Server · CVE-2015-6537
**Name of the Vulnerable Software and Affected Versions**
Epiphany Cardio Server version 3.3
**Description**
The issue allows remote attackers to execute arbitrary SQL commands via a crafted URL, specifically through a SQL injection vulnerability in the login page.
**Recommendations**
For Epiphany Cardio Server version 3.3, update to a version that includes a fix for the SQL injection vulnerability in the login page, or as a temporary workaround, consider restricting access to the login page to minimize the risk of exploitation.