CVE-2024-12307

MEDIUM

Unifiedtransform <2.0 - Privilege Escalation

Title source: llm
STIX 2.1

Description

A function-level access control vulnerability in Unifiedtransform version 2.0 and potentially earlier versions allows teachers to modify student personal data without proper authorization. The vulnerability exists due to missing access control checks in the student editing functionality. At the time of publication of the CVE no patch is available.

References (1)

Core 1
Core References

Scores

CVSS v3 4.3
EPSS 0.0023
EPSS Percentile 14.0%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N

CISA SSVC

Vulnrichment
Exploitation poc
Automatable no
Technical Impact partial

Details

CWE
CWE-284
Status published
Products (1)
Unifiedtransform/Unifiedtransform 2.0
Published Dec 09, 2024
Tracked Since Feb 18, 2026