Improper Authorization Vulnerability in Star Practice Management by Star
CVE-2020-28405

8.8HIGH

Key Information:

Vendor

Iris

Vendor
CVE Published:
29 January 2021

What is CVE-2020-28405?

An improper authorization vulnerability exists in Star Practice Management Web version 2019.2.0.6, permitting an unauthorized user to alter user privileges within the application. This vulnerability allows malicious actors to potentially elevate their own privileges to an administrative level or remove access from legitimate administrative accounts, compromising the integrity and security of the management system.

References

CVSS V3.1

Score:
8.8
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.
CVE-2020-28405 : Improper Authorization Vulnerability in Star Practice Management by Star