Skip to content
KitploitKITPLOIT
ToolsBlog
Submit
ToolsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

··Feeds·Contact·Privacy·© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories
CVE-2025-25617 — Proof-of-concept demonstrating an incorrect access control vulnerability in Unifiedtransform v2.0, allowing teachers to create syllabus entries reserved for administrators. | Kitploit
Tools/GitHubGitHub/armaansidana2003/cve-2025-25617
Privilege EscalationVulnerability AnalysisExploitationWeb Application ExploitationPenetration TestingLearning & Education
GitHubarmaansidana2003/cve-2025-25617

CVE-2025-25617

Proof-of-concept demonstrating an incorrect access control vulnerability in Unifiedtransform v2.0, allowing teachers to create syllabus entries reserved for administrators.

Most Popular

View all →

Discover the most used tools by our community.

Explore all tools

Browse our collection of tools

View all tools →
Share
View Repository
21 year agoNot yet reviewed

CVE-2025-25617

Unifiedtransform v2.0 is vulnerable to Incorrect Access Control, allowing teachers to create syllabus entries — a role intended only for administrators.

Vendor: Unifiedtransform


PoC

Step 1: Log in to the application as a Teacher.

Step 2: Browse to the following endpoint:
/syllabus/create

Step 3: Fill in the required fields and click on save.

Impact: Teachers gaining the ability to create syllabus entries can disrupt the academic workflow, as this functionality should be restricted to administrators only. This can lead to unauthorized and potentially incorrect syllabus data being added, creating confusion and mismanagement.


Vulnerability Type: Incorrect Access Control
Attack Type: Remote
Impact: Escalation of Privileges
Attack Vectors: Broken Access Control allows teachers to create syllabus entries without proper authorization.

Discoverer: Armaan Sidana

References:

  • Unifiedtransform Official Site
  • Unifiedtransform GitHub Repository
Download Tool