PT-2025-48177 · Unknown · Classroomio

Published

2025-11-26

·

Updated

2025-12-03

·

CVE-2025-65669

CVSS v3.1

9.1

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:H
Name of the Vulnerable Software and Affected Versions classroomio version 0.1.13
Description Student accounts can delete courses from the Explore page without proper authorization or authentication. This bypasses the restriction that course deletion should only be possible for administrators. The issue allows unauthorized course deletion.
Recommendations Update to a newer version that contains a fix for this vulnerability.

Exploit

Fix

Missing Authorization

Weakness Enumeration

Related Identifiers

CVE-2025-65669

Affected Products

Classroomio