The EMPOWER-TRANS* online platform, which has since gone live, experienced some initial difficulties, particularly with regard to security. These issues came to light after a team of G DATA specialists was commissioned to conduct a penetration test on the web application. It quickly became clear that the developers had some work to do.
Unfettered Access to the Admin Panel
The most pressing issue was that anyone with access who knew the correct web address could gain access to all of the platform’s features. For example, simply appending “/admin/role-management” to the web address was enough to gain access to the application’s administrator panel. Anyone with this knowledge can secretly and freely grant themselves administrator privileges and access all data—from patient names and medical histories to submitted documents, such as medical questionnaires.
This method also made it possible to search for specific patients. And all of this could be done without having to verify one’s identity at any point—using only a simple user account with no special privileges. From a data protection and security standpoint, this was a catastrophic flaw, which is why it is considered the most critical security vulnerability.
Further Gaps in the Armor
There were a total of 15 security vulnerabilities, and CVE numbers were requested for five of them due to their severity. For example, the website also allowed two-factor authentication (2FA) to be bypassed: The web application issued a valid session cookie before the entered 2FA code had even been verified. This made it possible to gain access even without entering a valid 2FA code.
Building Trust through Penetration Tests
Tests like these make it clear that security—not only in the healthcare sector but in all areas involving sensitive data—cannot be prioritized highly enough. The security vulnerabilities that were identified have since been addressed. After all, once confidential data falls into the wrong hands, the damage is irreversible. In this case, a test of the security measures was conducted prior to publication, using test data and no actual patient data. In the event of an actual incident, the resulting potential damage would be nearly impossible to estimate. Therefore, wherever personal data is processed, an independent and objective assessment of security is essential.
This is the only way we can build trust in digital solutions in the long run.
Translated from German using AI technologies.