CVE-2025-46203

An issue in Unifiedtransform v2.0 allows a remote attacker to escalate privileges via the /students/edit/{id} endpoint.
References
Configurations

Configuration 1 (hide)

cpe:2.3:a:changeweb:unifiedtransform:2.0:*:*:*:*:*:*:*

History

10 Jun 2025, 15:07

Type Values Removed Values Added
References () https://github.com/changeweb/Unifiedtransform - () https://github.com/changeweb/Unifiedtransform - Product
References () https://github.com/spbavarva/CVE-2025-46203 - () https://github.com/spbavarva/CVE-2025-46203 - Exploit, Third Party Advisory
First Time Changeweb unifiedtransform
Changeweb
CPE cpe:2.3:a:changeweb:unifiedtransform:2.0:*:*:*:*:*:*:*

05 Jun 2025, 20:12

Type Values Removed Values Added
Summary
  • (es) Un problema en Unifiedtransform v2.0 permite que un atacante remoto escale privilegios a través del endpoint /students/edit/{id}.

04 Jun 2025, 21:15

Type Values Removed Values Added
CWE CWE-266
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 6.5

04 Jun 2025, 20:15

Type Values Removed Values Added
New CVE

Information

Published : 2025-06-04 20:15

Updated : 2025-06-10 15:07


NVD link : CVE-2025-46203

Mitre link : CVE-2025-46203

CVE.ORG link : CVE-2025-46203


JSON object : View

Products Affected

changeweb

  • unifiedtransform
CWE
CWE-266

Incorrect Privilege Assignment