CVE-2025-25616
MEDIUMUnifiedtransform 2.0 - Improper Access Control via Exam Rule Edit Endpoint
Title source: llmExploitation Summary
EIP tracks 1 public exploit for CVE-2025-25616. PoCs published by armaansidana2003.
AI-analyzed exploit summary This repository provides a detailed writeup for CVE-2025-25616, an Incorrect Access Control vulnerability in Unifiedtransform v2.0. It describes how students can exploit an endpoint to modify exam rules, which should only be accessible by administrators.
Description
Unifiedtransform 2.0 is vulnerable to Incorrect Access Control, which allows students to modify rules for exams. The affected endpoint is /exams/edit-rule?exam_rule_id=1.
Exploits (1)
This repository provides a detailed writeup for CVE-2025-25616, an Incorrect Access Control vulnerability in Unifiedtransform v2.0. It describes how students can exploit an endpoint to modify exam rules, which should only be accessible by administrators.
References (2)
Scores
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N