Multiple access control vulnerabilities in Unifiedtransform version 2.0 and potentially earlier versions allow unauthorized access to personal information of students and teachers. The vulnerabilities include both function-level access control issues in list viewing endpoints and object-level access control issues in profile viewing endpoints. A malicious student user can access personal information of other students and teachers through these vulnerabilities. At the time of publication of the CVE no patch is available.
History

Mon, 09 Dec 2024 16:15:00 +0000

Type Values Removed Values Added
First Time appeared Unifiedtransform
Unifiedtransform unifiedtransform
CPEs cpe:2.3:a:unifiedtransform:unifiedtransform:*:*:*:*:*:*:*:*
Vendors & Products Unifiedtransform
Unifiedtransform unifiedtransform
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'poc', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Mon, 09 Dec 2024 09:00:00 +0000

Type Values Removed Values Added
Description Multiple access control vulnerabilities in Unifiedtransform version 2.0 and potentially earlier versions allow unauthorized access to personal information of students and teachers. The vulnerabilities include both function-level access control issues in list viewing endpoints and object-level access control issues in profile viewing endpoints. A malicious student user can access personal information of other students and teachers through these vulnerabilities. At the time of publication of the CVE no patch is available.
Title Access Control Vulnerabilities Allow Unauthorized Access to User Profiles in Unifiedtransform
Weaknesses CWE-284
CWE-639
References
Metrics cvssV3_1

{'score': 4.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N'}


cve-icon MITRE

Status: PUBLISHED

Assigner: NCSC.ch

Published: 2024-12-09T08:50:23.241Z

Updated: 2024-12-09T15:27:21.662Z

Reserved: 2024-12-06T15:05:33.280Z

Link: CVE-2024-12306

cve-icon Vulnrichment

Updated: 2024-12-09T15:27:15.832Z

cve-icon NVD

Status : Received

Published: 2024-12-09T09:15:05.293

Modified: 2024-12-09T09:15:05.293

Link: CVE-2024-12306

cve-icon Redhat

No data.