PT-2024-17536 · Unknown · Unifiedtransform
Published
2024-12-09
·
Updated
2024-12-09
·
CVE-2024-12306
CVSS v3.1
4.3
Medium
| Vector | AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N |
Name of the Vulnerable Software and Affected Versions
Unifiedtransform versions 2.0 and earlier
Description
The issue involves multiple access control vulnerabilities that allow unauthorized access to personal information of students and teachers. These vulnerabilities include function-level access control issues in list viewing endpoints and object-level access control issues in profile viewing endpoints. A malicious student user can exploit these vulnerabilities to access personal information of other students and teachers.
Recommendations
For Unifiedtransform versions 2.0 and earlier, at the moment, there is no information about a newer version that contains a fix for this vulnerability.
Exploit
Improper Access Control
IDOR
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Unifiedtransform