
Proof-of-concept exploit for CVE-2025-25614, an incorrect access control vulnerability in Unifiedtransform v2.0 allowing teachers to modify fellow teachers' data, leading to privilege escalation.
Incorrect Access Control in Unifiedtransform v2.0 leads to Privilege Escalation, allowing teachers to update the personal data of fellow teachers.
Vendor: Unifiedtransform
Step 1: Log in to the application as a Teacher.
Step 2: Browse to the following endpoint:
/teachers/edit/3
Step 3: Change the details and click on save.
Impact: This allows unauthorized modifications to other teachers' data, which should only be accessible by administrators. This can lead to significant data integrity issues and unauthorized privilege escalation.
Vulnerability Type: Incorrect Access Control
Attack Type: Remote
Impact: Escalation of Privileges
Attack Vectors: Broken Access Control allows teachers to modify data of fellow teachers.
Discoverer: Armaan Sidana
References: