PT-2025-9872 · Unknown · Unifiedtransform
Armaansidana2003
·
Publicado
2025-03-05
·
Atualizado
2025-06-24
·
CVE-2025-25621
CVSS v3.1
4.3
Média
| Vetor | AV:N/AC:L/PR:H/UI:R/S:U/C:L/I:L/A:L |
Name of the Vulnerable Software and Affected Versions
Unifiedtransform versions 2.X
Description
The issue allows teachers to take attendance of fellow teachers through the endpoint "/courses/teacher/index?teacher id=2&s...". This is due to incorrect access control.
Recommendations
For Unifiedtransform version 2.X, restrict access to the endpoint "/courses/teacher/index?teacher id=2&s..." to prevent unauthorized attendance taking. Consider implementing proper access controls to ensure that teachers can only take attendance for their own classes.
Exploit
Correção
Improper Access Control
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Enumeração de Fraquezas
Identificadores relacionados
Produtos afetados
Unifiedtransform