CVE-2025-25614

HIGH

Unifiedtransform 2.0 - Privilege Escalation via Incorrect Access Control

Title source: llm
STIX 2.1

Exploitation Summary

EIP tracks 1 public exploit for CVE-2025-25614. PoCs published by armaansidana2003.

AI-analyzed exploit summary This repository contains a writeup for CVE-2025-25614, detailing an incorrect access control vulnerability in Unifiedtransform v2.0 that allows teachers to escalate privileges by modifying other teachers' data. The PoC involves navigating to a specific endpoint and editing details without proper authorization checks.

Description

Incorrect Access Control in Unifiedtransform 2.0 leads to Privilege Escalation, which allows teachers to update the personal data of fellow teachers.

Exploits (1)

nomisec WRITEUP
by armaansidana2003 · poc
https://github.com/armaansidana2003/CVE-2025-25614

This repository contains a writeup for CVE-2025-25614, detailing an incorrect access control vulnerability in Unifiedtransform v2.0 that allows teachers to escalate privileges by modifying other teachers' data. The PoC involves navigating to a specific endpoint and editing details without proper authorization checks.

Classification
Writeup 90%
Attack Type
Auth Bypass
Complexity
Trivial
Reliability
Reliable
Target: Unifiedtransform v2.0
Auth required
Prerequisites: Valid teacher account credentials
devstral-2 · analyzed Feb 16, 2026 Full analysis →

References (2)

Core 2

Scores

CVSS v3 8.8
EPSS 0.0069
EPSS Percentile 48.0%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

CISA SSVC

Vulnrichment
Exploitation poc
Automatable no
Technical Impact total

Details

CWE
CWE-284
Status published
Products (1)
changeweb/unifiedtransform 2.0
Published Mar 10, 2025
Tracked Since Feb 18, 2026