cvelist/2020/28xxx/CVE-2020-28406.json

81 lines
2.5 KiB
JSON
Raw Normal View History

2020-11-10 20:01:36 +00:00
{
"CVE_data_meta": {
"ASSIGNER": "cve@mitre.org",
2021-01-29 07:00:40 +00:00
"ID": "CVE-2020-28406",
"STATE": "PUBLIC"
2020-11-10 20:01:36 +00:00
},
2021-01-29 07:00:40 +00:00
"affects": {
"vendor": {
"vendor_data": [
{
"product": {
"product_data": [
{
"product_name": "n/a",
"version": {
"version_data": [
{
"version_value": "n/a"
}
]
}
}
]
},
"vendor_name": "n/a"
}
]
}
},
"data_format": "MITRE",
"data_type": "CVE",
"data_version": "4.0",
2020-11-10 20:01:36 +00:00
"description": {
"description_data": [
{
"lang": "eng",
2021-01-29 07:00:40 +00:00
"value": "An improper authorization vulnerability exists in Star Practice Management Web version 2019.2.0.6, allowing an unauthorized user to access details about jobs he should not have access to via the Audit Trail Feature."
2020-11-10 20:01:36 +00:00
}
]
2021-01-29 07:00:40 +00:00
},
"problemtype": {
"problemtype_data": [
{
"description": [
{
"lang": "eng",
"value": "n/a"
}
]
}
]
},
"references": {
"reference_data": [
{
"url": "https://www.starpracticemanagement.com/",
"refsource": "MISC",
"name": "https://www.starpracticemanagement.com/"
},
{
"url": "https://excellium-services.com/cert-xlm-advisory/CVE-2020-28406",
"refsource": "MISC",
"name": "https://excellium-services.com/cert-xlm-advisory/CVE-2020-28406"
}
]
},
"impact": {
"cvss": {
"attackComplexity": "LOW",
"attackVector": "NETWORK",
"availabilityImpact": "NONE",
"confidentialityImpact": "HIGH",
"integrityImpact": "NONE",
"privilegesRequired": "LOW",
"scope": "UNCHANGED",
"userInteraction": "NONE",
"vectorString": "CVSS:3.1/AC:L/AV:N/A:N/C:H/I:N/PR:L/S:U/UI:N",
"version": "3.1"
}
2020-11-10 20:01:36 +00:00
}
}