« Volver al listado

CVE-2024-12306

Estado: AplazadaMedia (4.3)—

Multiple access control vulnerabilities in Unifiedtransform version 2.0 and potentially earlier versions allow unauthorized access to personal information of students and teachers. The vulnerabilities include both function-level access control issues in list viewing endpoints and object-level access control issues in profile viewing endpoints. A malicious student user can access personal information of other students and teachers through these vulnerabilities. At the time of publication of the CVE no patch is available.

CVSS

Probabilidad de explotación (EPSS)

EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).

Tecnologías afectadas (1)

⚠ Inferidas por IA a partir de la descripción — NVD aún no ha analizado esta CVE; no son CPE verificados.

CWE

Referencias

JSON original (NVD)

Mostrar
{
  "id": "CVE-2024-12306",
  "cveTags": [],
  "metrics": {
    "ssvcV203": [
      {
        "source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
        "ssvcData": {
          "id": "CVE-2024-12306",
          "role": "CISA Coordinator",
          "options": [
            {
              "exploitation": "poc"
            },
            {
              "automatable": "no"
            },
            {
              "technicalImpact": "partial"
            }
          ],
          "version": "2.0.3",
          "timestamp": "2024-12-09T15:26:07.359283Z"
        }
      }
    ],
    "cvssMetricV31": [
      {
        "type": "Secondary",
        "source": "vulnerability@ncsc.ch",
        "cvssData": {
          "scope": "UNCHANGED",
          "version": "3.1",
          "baseScore": 4.3,
          "attackVector": "NETWORK",
          "baseSeverity": "MEDIUM",
          "vectorString": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N",
          "integrityImpact": "NONE",
          "userInteraction": "NONE",
          "attackComplexity": "LOW",
          "availabilityImpact": "NONE",
          "privilegesRequired": "LOW",
          "confidentialityImpact": "LOW"
        },
        "impactScore": 1.4,
        "exploitabilityScore": 2.8
      }
    ]
  },
  "affected": [
    {
      "source": "vulnerability@ncsc.ch",
      "affectedData": [
        {
          "repo": "https://github.com/changeweb/Unifiedtransform",
          "vendor": "Unifiedtransform",
          "product": "Unifiedtransform",
          "versions": [
            {
              "status": "affected",
              "version": "2.0"
            }
          ],
          "programFiles": [
            "https://github.com/changeweb/Unifiedtransform/blob/fac7f551ff9284f9586a6644b057b76c1254c194/app/Http/Controllers/UserController.php#L90",
            "https://github.com/changeweb/Unifiedtransform/blob/fac7f551ff9284f9586a6644b057b76c1254c194/app/Http/Controllers/UserController.php#L98"
          ],
          "defaultStatus": "affected"
        }
      ]
    },
    {
      "source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
      "affectedData": [
        {
          "cpes": [
            "cpe:2.3:a:unifiedtransform:unifiedtransform:*:*:*:*:*:*:*:*"
          ],
          "vendor": "unifiedtransform",
          "product": "unifiedtransform",
          "versions": [
            {
              "status": "affected",
              "version": "2.0"
            }
          ],
          "defaultStatus": "unknown"
        }
      ]
    }
  ],
  "published": "2024-12-09T09:15:05.293",
  "references": [
    {
      "url": "https://huntr.com/bounties/90a7299e-9233-43fd-b666-7375c4fdbb3c",
      "source": "vulnerability@ncsc.ch"
    }
  ],
  "vulnStatus": "Deferred",
  "weaknesses": [
    {
      "type": "Secondary",
      "source": "vulnerability@ncsc.ch",
      "description": [
        {
          "lang": "en",
          "value": "CWE-284"
        },
        {
          "lang": "en",
          "value": "CWE-639"
        }
      ]
    }
  ],
  "descriptions": [
    {
      "lang": "en",
      "value": "Multiple access control vulnerabilities in Unifiedtransform version 2.0 and potentially earlier versions allow unauthorized access to personal information of students and teachers. The vulnerabilities include both function-level access control issues in list viewing endpoints and object-level access control issues in profile viewing endpoints. A malicious student user can access personal information of other students and teachers through these vulnerabilities. At the time of publication of the CVE no patch is available."
    },
    {
      "lang": "es",
      "value": "Varias vulnerabilidades de control de acceso en Unifiedtransform versión 2.0 y posiblemente versiones anteriores permiten el acceso no autorizado a la información personal de estudiantes y profesores. Las vulnerabilidades incluyen problemas de control de acceso a nivel de función en los endpoints de visualización de listas y problemas de control de acceso a nivel de objeto en los endpoints de visualización de perfiles. Un usuario estudiante malintencionado puede acceder a la información personal de otros estudiantes y profesores a través de estas vulnerabilidades. En el momento de la publicación de la CVE no hay ningún parche disponible."
    }
  ],
  "lastModified": "2026-06-17T06:59:28.127",
  "sourceIdentifier": "vulnerability@ncsc.ch"
}