Записи changeweb
9 опубликованных записей вендора changeweb.
Профиль для исследователя
- Попали в KEV
- 0 · 0 %
- С эксплойтом
- 0 · 0 %
- Pre-auth RCE
- 0
- С записью об исправлении
- 0 %
- Медиана: публикация → KEV
- Ни одна запись не попала в KEV
Повторяющиеся классы
- CWE-284 Improper Access Control6
- CWE-266 Incorrect Privilege Assignment2
- CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')1
Классы уязвимостей, которые чаще всего встречаются у этого вендора: куда смотреть.
CWEВсе записи
9 записей| Срочность | CVE | Уязвимость | Критичность | KEV | EPSS | Опубликовано |
|---|---|---|---|---|---|---|
39Наблюдать | CVE-2024-53573Эксплойта нет | Unifiedtransform v2.X is vulnerable to Incorrect Access Control.changeweb · unifiedtransform · CWE-284 | Критическая9,8 | — | 0,5 % | 26 февр. 2025 г. |
35Наблюдать | CVE-2025-25614Proof of concept | Incorrect Access Control in Unifiedtransform 2.0 leads to Privilege Escalation, which allows teachers to update the personal data of fellow changeweb · unifiedtransform · CWE-284 | Высокая8,8 | — | 0,8 % | 10 мар. 2025 г. |
26Наблюдать | CVE-2025-46204Proof of concept | An issue in Unifiedtransform v2.0 allows a remote attacker to escalate privileges via the /course/edit/{id} endpoint.changeweb · unifiedtransform · CWE-266 | Средняя6,5 | — | 0,4 % | 4 июн. 2025 г. |
26Наблюдать | CVE-2025-46203Proof of concept | An issue in Unifiedtransform v2.0 allows a remote attacker to escalate privileges via the /students/edit/{id} endpoint.changeweb · unifiedtransform · CWE-266 | Средняя6,5 | — | 0,4 % | 4 июн. 2025 г. |
21Наблюдать | CVE-2025-25620Proof of concept | Unifiedtransform 2.0 is vulnerable to Cross Site Scripting (XSS) in the Create assignment function.changeweb · unifiedtransform · CWE-79 | Средняя5,4 | — | 0,6 % | 10 мар. 2025 г. |
17Наблюдать | CVE-2025-25616Proof of concept | Unifiedtransform 2.0 is vulnerable to Incorrect Access Control, which allows students to modify rules for exams.changeweb · unifiedtransform · CWE-284 | Средняя4,3 | — | 0,4 % | 10 мар. 2025 г. |
17Наблюдать | CVE-2025-25621Proof of concept | Unifiedtransform 2.0 is vulnerable to Incorrect Access Control, which allows teachers to take attendance of fellow teachers.changeweb · unifiedtransform · CWE-284 | Средняя4,3 | — | 0,4 % | 17 мар. 2025 г. |
13Наблюдать | CVE-2025-25618Proof of concept | Incorrect Access Control in Unifiedtransform 2.0 leads to Privilege Escalation allowing the change of Section Name and Room Number by Teachechangeweb · unifiedtransform · CWE-284 | Низкая3,3 | — | 0,5 % | 17 мар. 2025 г. |
10Наблюдать | CVE-2025-25615Proof of concept | Unifiedtransform 2.0 is vulnerable to Incorrect Access Control which allows viewing attendance list for all class sections.changeweb · unifiedtransform · CWE-284 | Низкая2,7 | — | 0,5 % | 10 мар. 2025 г. |
- CVE-2024-5357339Наблюдать
Unifiedtransform v2.X is vulnerable to Incorrect Access Control.
КритическаяCVSS 9,8Эксплойта нетEPSS 1 %changeweb · unifiedtransform26 февр. 2025 г.
- CVE-2025-2561435Наблюдать
Incorrect Access Control in Unifiedtransform 2.0 leads to Privilege Escalation, which allows teachers to update the personal data of fellow
ВысокаяCVSS 8,8Proof of conceptEPSS 1 %changeweb · unifiedtransform10 мар. 2025 г.
- CVE-2025-4620426Наблюдать
An issue in Unifiedtransform v2.0 allows a remote attacker to escalate privileges via the /course/edit/{id} endpoint.
СредняяCVSS 6,5Proof of conceptEPSS 0 %changeweb · unifiedtransform4 июн. 2025 г.
- CVE-2025-4620326Наблюдать
An issue in Unifiedtransform v2.0 allows a remote attacker to escalate privileges via the /students/edit/{id} endpoint.
СредняяCVSS 6,5Proof of conceptEPSS 0 %changeweb · unifiedtransform4 июн. 2025 г.
- CVE-2025-2562021Наблюдать
Unifiedtransform 2.0 is vulnerable to Cross Site Scripting (XSS) in the Create assignment function.
СредняяCVSS 5,4Proof of conceptEPSS 1 %changeweb · unifiedtransform10 мар. 2025 г.
- CVE-2025-2561617Наблюдать
Unifiedtransform 2.0 is vulnerable to Incorrect Access Control, which allows students to modify rules for exams.
СредняяCVSS 4,3Proof of conceptEPSS 0 %changeweb · unifiedtransform10 мар. 2025 г.
- CVE-2025-2562117Наблюдать
Unifiedtransform 2.0 is vulnerable to Incorrect Access Control, which allows teachers to take attendance of fellow teachers.
СредняяCVSS 4,3Proof of conceptEPSS 0 %changeweb · unifiedtransform17 мар. 2025 г.
- CVE-2025-2561813Наблюдать
Incorrect Access Control in Unifiedtransform 2.0 leads to Privilege Escalation allowing the change of Section Name and Room Number by Teache
НизкаяCVSS 3,3Proof of conceptEPSS 0 %changeweb · unifiedtransform17 мар. 2025 г.
- CVE-2025-2561510Наблюдать
Unifiedtransform 2.0 is vulnerable to Incorrect Access Control which allows viewing attendance list for all class sections.
НизкаяCVSS 2,7Proof of conceptEPSS 0 %changeweb · unifiedtransform10 мар. 2025 г.