
Proof-of-concept demonstrating an incorrect access control vulnerability in Unifiedtransform v2.0, allowing teachers to create syllabus entries reserved for administrators.
Unifiedtransform v2.0 is vulnerable to Incorrect Access Control, allowing teachers to create syllabus entries — a role intended only for administrators.
Vendor: Unifiedtransform
Step 1: Log in to the application as a Teacher.
Step 2: Browse to the following endpoint:
/syllabus/create
Step 3: Fill in the required fields and click on save.
Impact: Teachers gaining the ability to create syllabus entries can disrupt the academic workflow, as this functionality should be restricted to administrators only. This can lead to unauthorized and potentially incorrect syllabus data being added, creating confusion and mismanagement.
Vulnerability Type: Incorrect Access Control
Attack Type: Remote
Impact: Escalation of Privileges
Attack Vectors: Broken Access Control allows teachers to create syllabus entries without proper authorization.
Discoverer: Armaan Sidana
References: