An issue in Unifiedtransform v2.0 allows a remote attacker to escalate privileges via the /students/edit/{id} endpoint.
A product incorrectly assigns a privilege to a particular actor, creating an unintended sphere of control for that actor.
Link | Tags |
---|---|
https://github.com/changeweb/Unifiedtransform | product |
https://github.com/spbavarva/CVE-2025-46203 | third party advisory exploit |