Function-Level Access Control Flaw in Unifiedtransform Affects Student Data Integrity
CVE-2024-12307
Key Information:
- Vendor
Unifiedtransform
- Status
- Vendor
- CVE Published:
- 9 December 2024
Badges
What is CVE-2024-12307?
CVE-2024-12307 identifies a critical function-level access control vulnerability in Unifiedtransform versions 2.0 and potentially earlier. This flaw enables authorized teachers to alter student personal data without the necessary permissions, primarily due to absent access control checks in the student editing feature. As of now, a patch to mitigate this vulnerability is not available, posing significant risks to the integrity of sensitive student information. Organizations using affected versions are strongly advised to assess their exposure and implement necessary security measures.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.
Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.
Affected Version(s)
Unifiedtransform 2.0
References
CVSS V3.1
Timeline
- ๐ก
Public PoC available
- ๐พ
Exploit known to exist
Vulnerability published
Vulnerability Reserved
