changeweb unifiedtransform の CVE(9 件)

CVE 件数: 9 CPE versions: View versions table

概要

本ページは changeweb unifiedtransform に影響する公開済み CVE(NVD の CPE 経由で関連付け)を列挙します。各行に深刻度指標・概要・公開日が含まれます。

表示中 19 / 9 CVE 件数
«« 先頭 « 前へ 1 / 1 次へ »
CVE 概要 ソース CVSS 最大値 EPSS(%) 公開 更新
CVE-2025-46204 An issue in Unifiedtransform v2.0 allows a remote attacker to escalate privileges via the /course/edit/{id} endpoint. [email protected] 6.5 0.09% 2025-06-04 2025-06-10
CVE-2025-46203 An issue in Unifiedtransform v2.0 allows a remote attacker to escalate privileges via the /students/edit/{id} endpoint. [email protected] 6.5 0.09% 2025-06-04 2025-06-10
CVE-2025-25621 Unifiedtransform 2.0 is vulnerable to Incorrect Access Control, which allows teachers to take attendance of fellow teachers. This affected endpoint is /courses/teacher/index?teacher_id=2&semester_id=1. [email protected] 4.3 0.05% 2025-03-17 2025-06-24
CVE-2025-25618 Incorrect Access Control in Unifiedtransform 2.0 leads to Privilege Escalation allowing the change of Section Name and Room Number by Teachers. [email protected] 3.3 0.08% 2025-03-17 2025-06-24
CVE-2025-25620 Unifiedtransform 2.0 is vulnerable to Cross Site Scripting (XSS) in the Create assignment function. [email protected] 5.4 0.25% 2025-03-10 2025-06-23
CVE-2025-25614 Incorrect Access Control in Unifiedtransform 2.0 leads to Privilege Escalation, which allows teachers to update the personal data of fellow teachers. [email protected] 8.8 0.40% 2025-03-10 2025-06-23
CVE-2025-25616 Unifiedtransform 2.0 is vulnerable to Incorrect Access Control, which allows students to modify rules for exams. The affected endpoint is /exams/edit-rule?exam_rule_id=1. [email protected] 4.3 0.57% 2025-03-10 2025-03-13
CVE-2025-25615 Unifiedtransform 2.0 is vulnerable to Incorrect Access Control which allows viewing attendance list for all class sections. [email protected] 2.7 0.42% 2025-03-10 2025-03-13
CVE-2024-53573 Unifiedtransform v2.X is vulnerable to Incorrect Access Control. Unauthorized users can access and manipulate endpoints intended exclusively for administrative use. This issue specifically affects teacher/edit/{id}. [email protected] 9.8 0.26% 2025-02-26 2025-04-07
«« 先頭 « 前へ 1 / 1 次へ »
cvelogic Threat Intelligence