CVE-2020-28403
Last modified
CVE-2020-28403 is a high-severity vulnerability rated 8.8/10 on the CVSS scale. A Cross-Site Request Forgery (CSRF) vulnerability exists in Star Practice Management Web version 2019.2.0.6, allowing an attacker to change the privileges of any user of the application. This can be used to grant himself administrative role or remove the administrative account of the application.. EPSS estimates a 0.66% chance of exploitation in the next 30 days.
Description
A Cross-Site Request Forgery (CSRF) vulnerability exists in Star Practice Management Web version 2019.2.0.6, allowing an attacker to change the privileges of any user of the application. This can be used to grant himself administrative role or remove the administrative account of the application.
Metrics
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Iris | Star | 2019.2.0.6 |
References
- https://excellium-services.com/cert-xlm-advisory/CVE-2020-28403Third Party Advisory
- https://excellium-services.com/cert-xlm-advisory/CVE-2020-28403Third Party Advisory
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2020-28403?
How severe is CVE-2020-28403?
How do I fix CVE-2020-28403?
Are you affected by CVE-2020-28403?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
