Access Control Vulnerabilities Allow Unauthorized Access to User Profiles in Unifiedtransform
Vulnerability Description
Multiple access control vulnerabilities in Unifiedtransform version 2.0 and potentially earlier versions allow unauthorized access to personal information of students and teachers. The vulnerabilities include both function-level access control issues in list viewing endpoints and object-level access control issues in profile viewing endpoints. A malicious student user can access personal information of other students and teachers through these vulnerabilities. At the time of publication of the CVE no patch is available.
Impact Analysis
Refer to official advisory for detailed impact metrics.
Remediation
Ensure systems are updated to the latest vendor-supplied patch levels.
Am I Vulnerable?
Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2024-12306
Credits & Attribution
The following person or organization is credited with identifying this vulnerability, as recorded in the NVD database:
- ZHAW Information Security Research Group
More from Unifiedtransform
View All →Affected Vendor
Unifiedtransform
View all reports →