PT-2015-7292 · Epiphany · Epiphany Cardio Server

Alex Lauerman

·

Published

2015-12-27

·

Updated

2015-12-28

·

CVE-2015-6537

CVSS v2.0

7.5

High

VectorAV:N/AC:L/Au:N/C:P/I:P/A:P
Name of the Vulnerable Software and Affected Versions Epiphany Cardio Server version 3.3
Description The issue allows remote attackers to execute arbitrary SQL commands via a crafted URL, specifically through a SQL injection vulnerability in the login page.
Recommendations For Epiphany Cardio Server version 3.3, update to a version that includes a fix for the SQL injection vulnerability in the login page, or as a temporary workaround, consider restricting access to the login page to minimize the risk of exploitation.

Fix

SQL injection

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2015-6537

Affected Products

Epiphany Cardio Server