Function-Level Access Control Flaw in Unifiedtransform Affects Student Data Integrity
CVE-2024-12307

4.3MEDIUM

Key Information:

Vendor
Unifiedtransform
Status
Unifiedtransform
Vendor
CVE Published:
9 December 2024

Badges

👾 Exploit Exists

Summary

CVE-2024-12307 identifies a critical function-level access control vulnerability in Unifiedtransform versions 2.0 and potentially earlier. This flaw enables authorized teachers to alter student personal data without the necessary permissions, primarily due to absent access control checks in the student editing feature. As of now, a patch to mitigate this vulnerability is not available, posing significant risks to the integrity of sensitive student information. Organizations using affected versions are strongly advised to assess their exposure and implement necessary security measures.

Affected Version(s)

Unifiedtransform 2.0

References

CVSS V3.1

Score:
4.3
Severity:
MEDIUM
Confidentiality:
None
Integrity:
Low
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged

Timeline

  • 🟡

    Public PoC available

  • 👾

    Exploit known to exist

  • Vulnerability published

  • Vulnerability Reserved

Credit

ZHAW Information Security Research Group
.