PT-2025-9868 · Unknown · Unifiedtransform
Armaan Sidana
·
Published
2025-03-05
·
Updated
2025-03-13
·
CVE-2025-25616
CVSS v3.1
7.6
High
| Vector | AV:N/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:L |
Name of the Vulnerable Software and Affected Versions
Unifiedtransform versions 2.X
Description
The issue allows students to modify exam rules due to incorrect access control. The affected endpoint is "/exams/edit-rule?exam rule id=1".
Recommendations
For Unifiedtransform version 2.X, restrict access to the "/exams/edit-rule" endpoint to prevent unauthorized modification of exam rules. Consider implementing proper access controls to ensure that only authorized users can modify exam rules.
Exploit
Fix
Improper Access Control
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Unifiedtransform