CVE-2024-12305

Source
https://cve.org/CVERecord?id=CVE-2024-12305
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2024-12305.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2024-12305
Published
2024-12-09T08:49:53.971Z
Modified
2026-08-12T03:51:34.146834551Z
Severity
  • 4.3 (Medium) CVSS_V3 - CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N CVSS Calculator
Summary
Object-Level Access Control Vulnerability Allows Unauthorized Access to Student Grades in Unifiedtransform
Details

An object-level access control vulnerability in Unifiedtransform version 2.0 and potentially earlier versions allows unauthorized access to student grades. A malicious student user can view grades of other students by manipulating the student_id parameter in the marks viewing endpoint. The vulnerability exists due to insufficient access control checks in MarkController.php. At the time of publication of the CVE no patch is available.

Database specific
{
    "cwe_ids": [
        "CWE-639"
    ],
    "cna_assigner": "NCSC.ch",
    "osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2024/12xxx/CVE-2024-12305.json"
}
References

Affected packages

Git / github.com/changeweb/unifiedtransform

Affected ranges

Type
GIT
Repo
https://github.com/changeweb/unifiedtransform
Events
Database specific
Show details
{
    "source": "AFFECTED_FIELD",
    "extracted_events": [
        {
            "introduced": "2.0"
        },
        {
            "last_affected": "2.0"
        }
    ]
}

Affected versions

2.*
2.0
v2.*
v2.0

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2024-12305.json"