CVE-2024-53573

Unifiedtransform v2.X is vulnerable to Incorrect Access Control. Unauthorized users can access and manipulate endpoints intended exclusively for administrative use. This issue specifically affects teacher/edit/{id}.
Configurations

Configuration 1 (hide)

cpe:2.3:a:changeweb:unifiedtransform:2.0:*:*:*:*:*:*:*

History

07 Apr 2025, 18:44

Type Values Removed Values Added
CPE cpe:2.3:a:changeweb:unifiedtransform:2.0:*:*:*:*:*:*:*
References () https://drive.google.com/file/d/14Or6QIpOeLEqdFm1mwxdE_NNCOwMmcFc/view - () https://drive.google.com/file/d/14Or6QIpOeLEqdFm1mwxdE_NNCOwMmcFc/view - Exploit
References () https://www.getastra.com/blog/vulnerability/improper-access-control-in-school-management-system-unifiedtransform/ - () https://www.getastra.com/blog/vulnerability/improper-access-control-in-school-management-system-unifiedtransform/ - Technical Description
First Time Changeweb unifiedtransform
Changeweb

04 Mar 2025, 21:15

Type Values Removed Values Added
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 9.8
References () https://drive.google.com/file/d/14Or6QIpOeLEqdFm1mwxdE_NNCOwMmcFc/view - () https://drive.google.com/file/d/14Or6QIpOeLEqdFm1mwxdE_NNCOwMmcFc/view -
CWE CWE-284
Summary
  • (es) Unifiedtransform v2.X es vulnerable a un control de acceso incorrecto. Los usuarios no autorizados pueden acceder y manipular endpoints destinados exclusivamente para uso administrativo. Este problema afecta específicamente a teacher/edit/{id}.

26 Feb 2025, 22:15

Type Values Removed Values Added
New CVE

Information

Published : 2025-02-26 22:15

Updated : 2025-04-07 18:44


NVD link : CVE-2024-53573

Mitre link : CVE-2024-53573

CVE.ORG link : CVE-2024-53573


JSON object : View

Products Affected

changeweb

  • unifiedtransform
CWE
CWE-284

Improper Access Control