CVE-2025-25616

MEDIUM

Unifiedtransform 2.0 - Improper Access Control via Exam Rule Edit Endpoint

Title source: llm
STIX 2.1

Exploitation Summary

EIP tracks 1 public exploit for CVE-2025-25616. PoCs published by armaansidana2003.

AI-analyzed exploit summary This repository provides a detailed writeup for CVE-2025-25616, an Incorrect Access Control vulnerability in Unifiedtransform v2.0. It describes how students can exploit an endpoint to modify exam rules, which should only be accessible by administrators.

Description

Unifiedtransform 2.0 is vulnerable to Incorrect Access Control, which allows students to modify rules for exams. The affected endpoint is /exams/edit-rule?exam_rule_id=1.

Exploits (1)

nomisec WRITEUP
by armaansidana2003 · poc
https://github.com/armaansidana2003/CVE-2025-25616

This repository provides a detailed writeup for CVE-2025-25616, an Incorrect Access Control vulnerability in Unifiedtransform v2.0. It describes how students can exploit an endpoint to modify exam rules, which should only be accessible by administrators.

Classification
Writeup 90%
Attack Type
Auth Bypass
Complexity
Trivial
Reliability
Reliable
Target: Unifiedtransform v2.0
Auth required
Prerequisites: Valid student credentials · Access to the vulnerable endpoint
devstral-2 · analyzed Feb 16, 2026 Full analysis →

References (2)

Core 2

Scores

CVSS v3 4.3
EPSS 0.0039
EPSS Percentile 30.7%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N

CISA SSVC

Vulnrichment
Exploitation poc
Automatable no
Technical Impact partial

Details

CWE
CWE-284
Status published
Products (1)
changeweb/unifiedtransform 2.0
Published Mar 10, 2025
Tracked Since Feb 18, 2026