changeweb records
9 published records for vendor changeweb.
Researcher profile
- Entered KEV
- 0 · 0%
- Weaponized
- 0 · 0%
- Pre-auth RCE
- 0
- With a fix record
- 0%
- Median publish → KEV
- No record has entered KEV
Recurring classes
- CWE-284 Improper Access Control6
- CWE-266 Incorrect Privilege Assignment2
- CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')1
The weakness classes this vendor ships most often: where to look.
CWEAttack profile
All records
9 records| Action | CVE | Vulnerability | Severity | KEV | EPSS | Published |
|---|---|---|---|---|---|---|
39Monitor | CVE-2024-53573No exploit | Unifiedtransform v2.X is vulnerable to Incorrect Access Control.changeweb · unifiedtransform · CWE-284 | Critical9.8 | — | 0.5% | Feb 26, 2025 |
35Monitor | CVE-2025-25614Proof of concept | Incorrect Access Control in Unifiedtransform 2.0 leads to Privilege Escalation, which allows teachers to update the personal data of fellow changeweb · unifiedtransform · CWE-284 | High8.8 | — | 0.8% | Mar 10, 2025 |
26Monitor | CVE-2025-46204Proof of concept | An issue in Unifiedtransform v2.0 allows a remote attacker to escalate privileges via the /course/edit/{id} endpoint.changeweb · unifiedtransform · CWE-266 | Medium6.5 | — | 0.4% | Jun 4, 2025 |
26Monitor | CVE-2025-46203Proof of concept | An issue in Unifiedtransform v2.0 allows a remote attacker to escalate privileges via the /students/edit/{id} endpoint.changeweb · unifiedtransform · CWE-266 | Medium6.5 | — | 0.4% | Jun 4, 2025 |
21Monitor | CVE-2025-25620Proof of concept | Unifiedtransform 2.0 is vulnerable to Cross Site Scripting (XSS) in the Create assignment function.changeweb · unifiedtransform · CWE-79 | Medium5.4 | — | 0.6% | Mar 10, 2025 |
17Monitor | CVE-2025-25616Proof of concept | Unifiedtransform 2.0 is vulnerable to Incorrect Access Control, which allows students to modify rules for exams.changeweb · unifiedtransform · CWE-284 | Medium4.3 | — | 0.4% | Mar 10, 2025 |
17Monitor | CVE-2025-25621Proof of concept | Unifiedtransform 2.0 is vulnerable to Incorrect Access Control, which allows teachers to take attendance of fellow teachers.changeweb · unifiedtransform · CWE-284 | Medium4.3 | — | 0.4% | Mar 17, 2025 |
13Monitor | CVE-2025-25618Proof of concept | Incorrect Access Control in Unifiedtransform 2.0 leads to Privilege Escalation allowing the change of Section Name and Room Number by Teachechangeweb · unifiedtransform · CWE-284 | Low3.3 | — | 0.5% | Mar 17, 2025 |
10Monitor | CVE-2025-25615Proof of concept | Unifiedtransform 2.0 is vulnerable to Incorrect Access Control which allows viewing attendance list for all class sections.changeweb · unifiedtransform · CWE-284 | Low2.7 | — | 0.5% | Mar 10, 2025 |
- CVE-2024-5357339Monitor
Unifiedtransform v2.X is vulnerable to Incorrect Access Control.
CriticalCVSS 9.8No exploitEPSS 1%changeweb · unifiedtransformFeb 26, 2025
- CVE-2025-2561435Monitor
Incorrect Access Control in Unifiedtransform 2.0 leads to Privilege Escalation, which allows teachers to update the personal data of fellow
HighCVSS 8.8Proof of conceptEPSS 1%changeweb · unifiedtransformMar 10, 2025
- CVE-2025-4620426Monitor
An issue in Unifiedtransform v2.0 allows a remote attacker to escalate privileges via the /course/edit/{id} endpoint.
MediumCVSS 6.5Proof of conceptEPSS 0%changeweb · unifiedtransformJun 4, 2025
- CVE-2025-4620326Monitor
An issue in Unifiedtransform v2.0 allows a remote attacker to escalate privileges via the /students/edit/{id} endpoint.
MediumCVSS 6.5Proof of conceptEPSS 0%changeweb · unifiedtransformJun 4, 2025
- CVE-2025-2562021Monitor
Unifiedtransform 2.0 is vulnerable to Cross Site Scripting (XSS) in the Create assignment function.
MediumCVSS 5.4Proof of conceptEPSS 1%changeweb · unifiedtransformMar 10, 2025
- CVE-2025-2561617Monitor
Unifiedtransform 2.0 is vulnerable to Incorrect Access Control, which allows students to modify rules for exams.
MediumCVSS 4.3Proof of conceptEPSS 0%changeweb · unifiedtransformMar 10, 2025
- CVE-2025-2562117Monitor
Unifiedtransform 2.0 is vulnerable to Incorrect Access Control, which allows teachers to take attendance of fellow teachers.
MediumCVSS 4.3Proof of conceptEPSS 0%changeweb · unifiedtransformMar 17, 2025
- CVE-2025-2561813Monitor
Incorrect Access Control in Unifiedtransform 2.0 leads to Privilege Escalation allowing the change of Section Name and Room Number by Teache
LowCVSS 3.3Proof of conceptEPSS 0%changeweb · unifiedtransformMar 17, 2025
- CVE-2025-2561510Monitor
Unifiedtransform 2.0 is vulnerable to Incorrect Access Control which allows viewing attendance list for all class sections.
LowCVSS 2.7Proof of conceptEPSS 0%changeweb · unifiedtransformMar 10, 2025