Vulnerabilities > Iris > Star Practice Management > High

DATE CVE VULNERABILITY TITLE RISK
2021-01-29 CVE-2020-28405 Unspecified vulnerability in Iris Star Practice Management 2019.2.0.6
An improper authorization vulnerability exists in Star Practice Management Web version 2019.2.0.6, allowing an unauthorized user to change the privileges of any user of the application.
network
low complexity
iris
8.8
2021-01-29 CVE-2020-28402 Unspecified vulnerability in Iris Star Practice Management 2019.2.0.6
An improper authorization vulnerability exists in Star Practice Management Web version 2019.2.0.6, allowing an unauthorized user to access Launcher Configuration Panel.
network
low complexity
iris
8.8