{"description":"Trending threats, MITRE ATT\u0026CK coverage, and detection metadata. Fed continuously.","favicon":"https://feed.craftedsignal.io/favicon-32x32.png","feed_url":"https://feed.craftedsignal.io/vendors/changeweb/feed.json","home_page_url":"https://feed.craftedsignal.io/","icon":"https://feed.craftedsignal.io/apple-touch-icon.png","items":[{"_cs_actors":[],"_cs_cpes":["cpe:2.3:a:changeweb:unifiedtransform:2.0:*:*:*:*:*:*:*"],"_cs_cves":[{"cvss":6.5,"id":"CVE-2025-46203"}],"_cs_exploited":false,"_cs_has_poc":false,"_cs_poc_references":[],"_cs_products":["Unifiedtransform (2.0)"],"_cs_severities":["medium"],"_cs_tags":[],"_cs_type":"advisory","_cs_vendors":["Changeweb"],"content_html":"\u003cp\u003eChangeweb Unifiedtransform version 2.0 is susceptible to an incorrect access control vulnerability tracked as CVE-2025-46203. The issue resides within the UserController's editStudents() method, which fails to properly validate user permissions when accessing the /students/edit/{id} endpoint. This flaw permits non-administrative users, including teachers and students, to submit unauthorized modifications to student records that should be restricted to administrative roles. The vulnerability is exploitable over the network without requiring prior authentication beyond a valid (low-privilege) user session, leading to potential data integrity compromise and privilege escalation within the school management system.\u003c/p\u003e\n\u003ch2 id=\"attack-chain\"\u003eAttack Chain\u003c/h2\u003e\n\u003col\u003e\n\u003cli\u003eAttacker authenticates to the Unifiedtransform application using standard student or teacher credentials.\u003c/li\u003e\n\u003cli\u003eAttacker enumerates existing student IDs through the application UI or by observing URL patterns.\u003c/li\u003e\n\u003cli\u003eAttacker constructs a malicious HTTP GET or POST request targeting the /students/edit/{id} endpoint.\u003c/li\u003e\n\u003cli\u003eThe application processes the request in the UserController.editStudents() method without verifying if the user has administrative privileges.\u003c/li\u003e\n\u003cli\u003eThe backend executes the database update operation using the attacker-supplied data.\u003c/li\u003e\n\u003cli\u003eThe application returns a successful response, confirming the unauthorized modification of the target student record.\u003c/li\u003e\n\u003cli\u003eAttacker successfully escalates privileges or corrupts student record data.\u003c/li\u003e\n\u003c/ol\u003e\n\u003ch2 id=\"impact\"\u003eImpact\u003c/h2\u003e\n\u003cp\u003eSuccessful exploitation allows unauthorized users to modify sensitive student information, leading to data integrity issues. This privilege escalation vector undermines the administrative access control model of the Unifiedtransform platform, potentially allowing malicious actors to manipulate grades, personal identifiers, or academic records.\u003c/p\u003e\n\u003ch2 id=\"recommendation\"\u003eRecommendation\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eMonitor web server logs for HTTP requests to the /students/edit/ pattern originating from accounts not associated with administrative roles.\u003c/li\u003e\n\u003cli\u003eAudit access controls within the UserController logic to ensure that editStudents() enforces authorization checks.\u003c/li\u003e\n\u003cli\u003eImplement strict session-based role validation for all administrative endpoints.\u003c/li\u003e\n\u003cli\u003ePatch or update the Unifiedtransform instance to a secure version if available.\u003c/li\u003e\n\u003c/ul\u003e\n","date_modified":"2026-08-28T00:20:26Z","date_published":"2026-08-28T00:20:26Z","id":"https://feed.craftedsignal.io/briefs/2026-08-cve-2025-46203/","summary":"Changeweb Unifiedtransform version 2.0 contains an incorrect access control vulnerability allowing unprivileged users to modify student records via the /students/edit/{id} endpoint.","title":"Incorrect Access Control in Changeweb Unifiedtransform","url":"https://feed.craftedsignal.io/briefs/2026-08-cve-2025-46203/"}],"language":"en","title":"CraftedSignal Threat Feed - Changeweb","version":"https://jsonfeed.org/version/1.1"}