
Proof-of-concept exploit for CVE-2025-25621, an incorrect access control vulnerability in Unifiedtransform v2.0 allowing teachers to take attendance for other teachers, leading to privilege escalation.
Unifiedtransform v2.0 is vulnerable to Incorrect Access Control, allowing teachers to take attendance of fellow teachers through the endpoint /courses/teacher/index?teacher_id=2&semester_id=1.
Vendor: Unifiedtransform
Step 1: Log in to the application as a Teacher.
Step 2: Navigate to the endpoint /courses/teacher/index?teacher_id=2&semester_id=1 (Change the Teacher ID).
Step 3: Click on "Take Attendance" and then click on "Save."
Impact: Teachers can manipulate attendance records for other teachers, which should only be possible for admins, leading to privilege escalation and potential misuse.
Vulnerability Type: Incorrect Access Control
Attack Type: Remote
Impact: Privilege Escalation
Attack Vectors: Broken access control, allowing teachers to take attendance for other teachers.
Discoverer: Armaan Sidana
References: