CVE-2020-28406
Last modified
CVE-2020-28406 is a medium-severity vulnerability rated 6.5/10 on the CVSS scale. An improper authorization vulnerability exists in Star Practice Management Web version 2019.2.0.6, allowing an unauthorized user to access details about jobs he should not have access to via the Audit Trail Feature.. EPSS estimates a 1.34% chance of exploitation in the next 30 days.
Description
An improper authorization vulnerability exists in Star Practice Management Web version 2019.2.0.6, allowing an unauthorized user to access details about jobs he should not have access to via the Audit Trail Feature.
Metrics
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Iris | Star Practice Management | 2019.2.0.6 |
References
- https://excellium-services.com/cert-xlm-advisory/CVE-2020-28406Third Party Advisory
- https://excellium-services.com/cert-xlm-advisory/CVE-2020-28406Third Party Advisory
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2020-28406?
How severe is CVE-2020-28406?
How do I fix CVE-2020-28406?
Are you affected by CVE-2020-28406?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
