Back to Database
Status published
Medium
CVE-2020-28401
An improper authorization vulnerability exists in Star Practice Management Web...
Vulnerability Description
An improper authorization vulnerability exists in Star Practice Management Web version 2019.2.0.6, allowing an unauthorized user to access WIP details about jobs he should not have access to.
Impact Analysis
Refer to official advisory for detailed impact metrics.
Remediation
Ensure systems are updated to the latest vendor-supplied patch levels.
THREAT MONITOR
Am I Vulnerable?
Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2020-28401
Credits & Attribution
No credits recorded in the NVD database.
References
More from iris
View All →CVE-2022-37028
ISAMS 22.2.3.2 is prone to stored Cross-site Scripting (XSS) attack...
Unknown
0
CVE-2020-28406
An improper authorization vulnerability exists in Star Practice Management Web...
Medium
6.5
CVE-2020-28405
An improper authorization vulnerability exists in Star Practice Management Web...
High
8.8
CVE-2020-28404
An improper authorization vulnerability exists in Star Practice Management Web...
Medium
6.5
CVE-2020-28403
A Cross-Site Request Forgery (CSRF) vulnerability exists in Star Practice...
High
8
Affected Vendor
iris
View all reports →Affected Software
star practice management
Vulnerable Versions:
2019.2.0.6
Timeline
Official Publish:
January 29th, 2021
Last Modified:
May 30th, 2025
Added to House:
July 21st, 2026
CVSS Vectors
V3:
CVSS:3.1/AC:L/AV:N/A:N/C:H/I:N/PR:L/S:U/UI:N
Weaknesses (CWE)
No CWE data available
MITRE ATT&CK TTPs
No associated TTPs found for this vulnerability.