Description
An object-level access control vulnerability in Unifiedtransform version 2.0 and potentially earlier versions allows unauthorized access to student grades. A malicious student user can view grades of other students by manipulating the student_id parameter in the marks viewing endpoint. The vulnerability exists due to insufficient access control checks in MarkController.php. At the time of publication of the CVE no patch is available.
Published: 2024-12-09
Score: 4.3 Medium
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

No analysis available yet.

Remediation

No remediation available yet.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
EUVD EUVD EUVD-2024-50758 An object-level access control vulnerability in Unifiedtransform version 2.0 and potentially earlier versions allows unauthorized access to student grades. A malicious student user can view grades of other students by manipulating the student_id parameter in the marks viewing endpoint. The vulnerability exists due to insufficient access control checks in MarkController.php. At the time of publication of the CVE no patch is available.
History

Tue, 15 Jul 2025 13:45:00 +0000

Type Values Removed Values Added
Metrics epss

{'score': 0.00058}

epss

{'score': 0.00065}


Mon, 09 Dec 2024 16:15:00 +0000

Type Values Removed Values Added
First Time appeared Unifiedtransform
Unifiedtransform unifiedtransform
CPEs cpe:2.3:a:unifiedtransform:unifiedtransform:*:*:*:*:*:*:*:*
Vendors & Products Unifiedtransform
Unifiedtransform unifiedtransform
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'poc', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Mon, 09 Dec 2024 09:00:00 +0000

Type Values Removed Values Added
Description An object-level access control vulnerability in Unifiedtransform version 2.0 and potentially earlier versions allows unauthorized access to student grades. A malicious student user can view grades of other students by manipulating the student_id parameter in the marks viewing endpoint. The vulnerability exists due to insufficient access control checks in MarkController.php. At the time of publication of the CVE no patch is available.
Title Object-Level Access Control Vulnerability Allows Unauthorized Access to Student Grades in Unifiedtransform
Weaknesses CWE-639
References
Metrics cvssV3_1

{'score': 4.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N'}


Subscriptions

Unifiedtransform Unifiedtransform
cve-icon MITRE

Status: PUBLISHED

Assigner: NCSC.ch

Published:

Updated: 2024-12-09T15:30:21.269Z

Reserved: 2024-12-06T15:05:32.039Z

Link: CVE-2024-12305

cve-icon Vulnrichment

Updated: 2024-12-09T15:30:12.676Z

cve-icon NVD

Status : Deferred

Published: 2024-12-09T09:15:04.970

Modified: 2026-04-15T00:35:42.020

Link: CVE-2024-12305

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

No data.

Weaknesses