Changeweb
Changeweb Unifiedtransform: vulnerabilidades y CVE
Changeweb Unifiedtransform tiene 14 vulnerabilidades publicadas, 0 de ellas en los últimos 12 meses. 1 son críticas y 0 figuran en el catálogo de explotación activa de CISA.
CVE14
Últimos 12 meses0
Críticas1
Explotadas activamente0
Todas las vulnerabilidades en el catálogo →⭐ Seguir esta tecnología
Últimas vulnerabilidades
| CVE | Severidad | EPSS | Explotación activa | Publicada | Descripción |
|---|---|---|---|---|---|
| CVE-2025-46204 | Media (6.5) | 0.39% | — | 4 jun 2025 | An issue in Unifiedtransform v2.0 allows a remote attacker to escalate privileges via the /course/edit/{id} endpoint. |
| CVE-2025-46203 | Media (6.5) | 0.36% | — | 4 jun 2025 | An issue in Unifiedtransform v2.0 allows a remote attacker to escalate privileges via the /students/edit/{id} endpoint. |
| CVE-2025-25621 | Media (4.3) | 0.38% | — | 17 mar 2025 | Unifiedtransform 2.0 is vulnerable to Incorrect Access Control, which allows teachers to take attendance of fellow teachers. This affected endpoint is /courses/teacher/index?teacher_id=2&semester_id=1. |
| CVE-2025-25618 | Baja (3.3) | 0.46% | — | 17 mar 2025 | Incorrect Access Control in Unifiedtransform 2.0 leads to Privilege Escalation allowing the change of Section Name and Room Number by Teachers. |
| CVE-2025-25620 | Media (5.4) | 0.56% | — | 10 mar 2025 | Unifiedtransform 2.0 is vulnerable to Cross Site Scripting (XSS) in the Create assignment function. |
| CVE-2025-25614 | Alta (8.8) | 0.78% | — | 10 mar 2025 | Incorrect Access Control in Unifiedtransform 2.0 leads to Privilege Escalation, which allows teachers to update the personal data of fellow teachers. |
| CVE-2025-25616 | Media (4.3) | 0.41% | — | 10 mar 2025 | Unifiedtransform 2.0 is vulnerable to Incorrect Access Control, which allows students to modify rules for exams. The affected endpoint is /exams/edit-rule?exam_rule_id=1. |
| CVE-2025-25615 | Baja (2.7) | 0.48% | — | 10 mar 2025 | Unifiedtransform 2.0 is vulnerable to Incorrect Access Control which allows viewing attendance list for all class sections. |
| CVE-2025-25617 | Media (4.3) | 0.44% | — | 7 mar 2025 | Incorrect Access Control in Unifiedtransform 2.X leads to Privilege Escalation allowing teachers to create syllabus. |
| CVE-2024-53573 | Crítica (9.8) | 0.54% | — | 26 feb 2025 | Unifiedtransform v2.X is vulnerable to Incorrect Access Control. Unauthorized users can access and manipulate endpoints intended exclusively for administrative use. This issue specifically affects teacher/edit/{id}. |
| CVE-2024-12307 | Media (4.3) | 0.24% | — | 9 dic 2024 | A function-level access control vulnerability in Unifiedtransform version 2.0 and potentially earlier versions allows teachers to modify student personal data without proper authorization. The vulnerability exists due… |
| CVE-2024-12306 | Media (4.3) | 0.26% | — | 9 dic 2024 | Multiple access control vulnerabilities in Unifiedtransform version 2.0 and potentially earlier versions allow unauthorized access to personal information of students and teachers. The vulnerabilities include both… |
| CVE-2024-12305 | Media (4.3) | 0.26% | — | 9 dic 2024 | An object-level access control vulnerability in Unifiedtransform version 2.0 and potentially earlier versions allows unauthorized access to student grades. A malicious student user can view grades of other students by… |
| CVE-2024-27665 | Media (5.4) | 0.43% | — | 9 abr 2024 | Unifiedtransform v2.X is vulnerable to Stored Cross-Site Scripting (XSS) via file upload feature in Syllabus module. |