PT-2025-9872 · Unknown · Unifiedtransform
Armaansidana2003
·
Published
2025-03-05
·
Updated
2025-06-24
·
CVE-2025-25621
CVSS v3.1
4.3
Medium
| Vector | AV:N/AC:L/PR:H/UI:R/S:U/C:L/I:L/A:L |
Name of the Vulnerable Software and Affected Versions
Unifiedtransform versions 2.X
Description
The issue allows teachers to take attendance of fellow teachers through the endpoint "/courses/teacher/index?teacher id=2&s...". This is due to incorrect access control.
Recommendations
For Unifiedtransform version 2.X, restrict access to the endpoint "/courses/teacher/index?teacher id=2&s..." to prevent unauthorized attendance taking. Consider implementing proper access controls to ensure that teachers can only take attendance for their own classes.
Exploit
Fix
Improper Access Control
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Unifiedtransform