Skip to content
KitploitKITPLOIT
ToolsBlog
Submit
ToolsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

··Feeds·Contact·Privacy·© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories
CVE-2025-25621 | Kitploit
Tools/GitHubGitHub/armaansidana2003/cve-2025-25621
Privilege EscalationVulnerability AnalysisWeb Application ExploitationPenetration TestingMisconfigurationLearning & Education
GitHubarmaansidana2003/cve-2025-25621

CVE-2025-25621

View Repository
1 year agoNot yet reviewed

Most Popular

View all →

Discover the most used tools by our community.

Explore all tools

Browse our collection of tools

View all tools →
Share

CVE-2025-25621

Unifiedtransform v2.0 is vulnerable to Incorrect Access Control, allowing teachers to take attendance of fellow teachers through the endpoint /courses/teacher/index?teacher_id=2&semester_id=1.

Vendor: Unifiedtransform


PoC

Step 1: Log in to the application as a Teacher.

Step 2: Navigate to the endpoint /courses/teacher/index?teacher_id=2&semester_id=1 (Change the Teacher ID).

Step 3: Click on "Take Attendance" and then click on "Save."

Impact: Teachers can manipulate attendance records for other teachers, which should only be possible for admins, leading to privilege escalation and potential misuse.


Vulnerability Type: Incorrect Access Control
Attack Type: Remote
Impact: Privilege Escalation
Attack Vectors: Broken access control, allowing teachers to take attendance for other teachers.

Discoverer: Armaan Sidana

References:

  • Unifiedtransform Official Site
  • Unifiedtransform GitHub Repository
Download Tool