Vulnerabilities > Iris

DATE CVE VULNERABILITY TITLE RISK
2022-09-27 CVE-2022-37028 Cross-site Scripting vulnerability in Iris Isams 22.2.3.2
ISAMS 22.2.3.2 is prone to stored Cross-site Scripting (XSS) attack on the title field for groups, allowing an attacker to store a JavaScript payload that will be executed when another user uses the application.
network
low complexity
iris CWE-79
5.4
2021-01-29 CVE-2020-28406 Incorrect Authorization vulnerability in Iris Star Practice Management 2019.2.0.6
An improper authorization vulnerability exists in Star Practice Management Web version 2019.2.0.6, allowing an unauthorized user to access details about jobs he should not have access to via the Audit Trail Feature.
network
low complexity
iris CWE-863
4.0
2021-01-29 CVE-2020-28405 Incorrect Authorization vulnerability in Iris Star Practice Management 2019.2.0.6
An improper authorization vulnerability exists in Star Practice Management Web version 2019.2.0.6, allowing an unauthorized user to change the privileges of any user of the application.
network
low complexity
iris CWE-863
6.5
2021-01-29 CVE-2020-28404 Incorrect Authorization vulnerability in Iris Star Practice Management 2019.2.0.6
An improper authorization vulnerability exists in Star Practice Management Web version 2019.2.0.6, allowing an unauthorized user to access the Billing page without the appropriate privileges.
network
low complexity
iris CWE-863
4.0
2021-01-29 CVE-2020-28403 Cross-Site Request Forgery (CSRF) vulnerability in Iris Star 2019.2.0.6
A Cross-Site Request Forgery (CSRF) vulnerability exists in Star Practice Management Web version 2019.2.0.6, allowing an attacker to change the privileges of any user of the application.
network
iris CWE-352
6.8
2021-01-29 CVE-2020-28402 Incorrect Authorization vulnerability in Iris Star Practice Management 2019.2.0.6
An improper authorization vulnerability exists in Star Practice Management Web version 2019.2.0.6, allowing an unauthorized user to access Launcher Configuration Panel.
network
low complexity
iris CWE-863
6.5
2021-01-29 CVE-2020-28401 Incorrect Authorization vulnerability in Iris Star Practice Management 2019.2.0.6
An improper authorization vulnerability exists in Star Practice Management Web version 2019.2.0.6, allowing an unauthorized user to access WIP details about jobs he should not have access to.
network
low complexity
iris CWE-863
4.0