VendorsChangewebunifiedtransform2.0
Vulnerabilities

Changeweb Unifiedtransform 2.0

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

9CVEs
CVE-2024-53573
Unifiedtransform v2.X is vulnerable to Incorrect Access Control. Unauthorized users can access and manipulate endpoints intended exclusively for administrative use. This issue specifically affects teacher/edit/{id}.
Published 2025-02-26 · Analyzed
9.8EPSS 0.005
CVE-2025-25614
Incorrect Access Control in Unifiedtransform 2.0 leads to Privilege Escalation, which allows teachers to update the personal data of fellow teachers.
Published 2025-03-10 · Analyzed
8.8EPSS 0.008
CVE-2025-25616
Unifiedtransform 2.0 is vulnerable to Incorrect Access Control, which allows students to modify rules for exams. The affected endpoint is /exams/edit-rule?exam_rule_id=1.
Published 2025-03-10 · Analyzed
7.6EPSS 0.004
CVE-2025-46204
An issue in Unifiedtransform v2.0 allows a remote attacker to escalate privileges via the /course/edit/{id} endpoint.
Published 2025-06-04 · Analyzed
6.5EPSS 0.004
CVE-2025-46203
An issue in Unifiedtransform v2.0 allows a remote attacker to escalate privileges via the /students/edit/{id} endpoint.
Published 2025-06-04 · Analyzed
6.5EPSS 0.004
CVE-2025-25615
Unifiedtransform 2.0 is vulnerable to Incorrect Access Control which allows viewing attendance list for all class sections.
Published 2025-03-10 · Analyzed
6.0EPSS 0.005
CVE-2025-25620
Unifiedtransform 2.0 is vulnerable to Cross Site Scripting (XSS) in the Create assignment function.
Published 2025-03-10 · Analyzed
5.4EPSS 0.006
CVE-2025-25621
Unifiedtransform 2.0 is vulnerable to Incorrect Access Control, which allows teachers to take attendance of fellow teachers. This affected endpoint is /courses/teacher/index?teacher_id=2&semester_id=1.
Published 2025-03-17 · Analyzed
4.3EPSS 0.004
CVE-2025-25618
Incorrect Access Control in Unifiedtransform 2.0 leads to Privilege Escalation allowing the change of Section Name and Room Number by Teachers.
Published 2025-03-17 · Analyzed
3.3EPSS 0.005