Unifiedtransform 2.0 is vulnerable to Incorrect Access Control, which allows students to modify rules for exams. The affected endpoint is /exams/edit-rule?exam_rule_id=1.
Affected Software
| Name | Vendor | Start Version | End Version |
|---|
| Unifiedtransform | Changeweb | 2.0 (including) | 2.0 (including) |
References