Vulnerabilities > Iris > Star Practice Management
DATE | CVE | VULNERABILITY TITLE | RISK |
---|---|---|---|
2021-01-29 | CVE-2020-28406 | Incorrect Authorization vulnerability in Iris Star Practice Management 2019.2.0.6 An improper authorization vulnerability exists in Star Practice Management Web version 2019.2.0.6, allowing an unauthorized user to access details about jobs he should not have access to via the Audit Trail Feature. | 4.0 |
2021-01-29 | CVE-2020-28405 | Incorrect Authorization vulnerability in Iris Star Practice Management 2019.2.0.6 An improper authorization vulnerability exists in Star Practice Management Web version 2019.2.0.6, allowing an unauthorized user to change the privileges of any user of the application. | 6.5 |
2021-01-29 | CVE-2020-28404 | Incorrect Authorization vulnerability in Iris Star Practice Management 2019.2.0.6 An improper authorization vulnerability exists in Star Practice Management Web version 2019.2.0.6, allowing an unauthorized user to access the Billing page without the appropriate privileges. | 4.0 |
2021-01-29 | CVE-2020-28402 | Incorrect Authorization vulnerability in Iris Star Practice Management 2019.2.0.6 An improper authorization vulnerability exists in Star Practice Management Web version 2019.2.0.6, allowing an unauthorized user to access Launcher Configuration Panel. | 6.5 |
2021-01-29 | CVE-2020-28401 | Incorrect Authorization vulnerability in Iris Star Practice Management 2019.2.0.6 An improper authorization vulnerability exists in Star Practice Management Web version 2019.2.0.6, allowing an unauthorized user to access WIP details about jobs he should not have access to. | 4.0 |