An object-level access control vulnerability in Unifiedtransform version 2.0 and potentially earlier versions allows unauthorized access to student grades. A malicious student user can view grades of other students by manipulating the student_id parameter in the marks viewing endpoint. The vulnerability exists due to insufficient access control checks in MarkController.php. At the time of publication of the CVE no patch is available.
History

Mon, 09 Dec 2024 16:15:00 +0000

Type Values Removed Values Added
First Time appeared Unifiedtransform
Unifiedtransform unifiedtransform
CPEs cpe:2.3:a:unifiedtransform:unifiedtransform:*:*:*:*:*:*:*:*
Vendors & Products Unifiedtransform
Unifiedtransform unifiedtransform
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'poc', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Mon, 09 Dec 2024 09:00:00 +0000

Type Values Removed Values Added
Description An object-level access control vulnerability in Unifiedtransform version 2.0 and potentially earlier versions allows unauthorized access to student grades. A malicious student user can view grades of other students by manipulating the student_id parameter in the marks viewing endpoint. The vulnerability exists due to insufficient access control checks in MarkController.php. At the time of publication of the CVE no patch is available.
Title Object-Level Access Control Vulnerability Allows Unauthorized Access to Student Grades in Unifiedtransform
Weaknesses CWE-639
References
Metrics cvssV3_1

{'score': 4.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N'}


cve-icon MITRE

Status: PUBLISHED

Assigner: NCSC.ch

Published: 2024-12-09T08:49:53.971Z

Updated: 2024-12-09T15:30:21.269Z

Reserved: 2024-12-06T15:05:32.039Z

Link: CVE-2024-12305

cve-icon Vulnrichment

Updated: 2024-12-09T15:30:12.676Z

cve-icon NVD

Status : Received

Published: 2024-12-09T09:15:04.970

Modified: 2024-12-09T09:15:04.970

Link: CVE-2024-12305

cve-icon Redhat

No data.