Access Control Flaw in Unifiedtransform Affects Student Privacy
CVE-2024-12305
Key Information:
- Vendor
Unifiedtransform
- Status
- Vendor
- CVE Published:
- 9 December 2024
Badges
What is CVE-2024-12305?
CVE-2024-12305 is a high-severity access control vulnerability found in Unifiedtransform versions 2.0 and potentially earlier. This flaw allows an attacker, specifically a malicious student, to gain unauthorized visibility into the grades of other students. By manipulating the 'student_id' parameter at the marks viewing endpoint, the attacker can bypass core access control mechanisms due to inadequate protections implemented in MarkController.php. This vulnerability poses significant risks to student privacy and data security. Currently, there are no patches available to mitigate this issue.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.
Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.
Affected Version(s)
Unifiedtransform 2.0
References
CVSS V3.1
Timeline
- ๐ก
Public PoC available
- ๐พ
Exploit known to exist
Vulnerability published
Vulnerability Reserved
