Unifiedtransform 2.0 is vulnerable to Incorrect Access Control, which allows students to modify rules for exams. The affected endpoint is /exams/edit-rule?exam_rule_id=1.
Affected Software
Name |
Vendor |
Start Version |
End Version |
Unifiedtransform |
Changeweb |
2.0 (including) |
2.0 (including) |
References