PT-2026-34882 · Unknown · Classroomio

Published

2026-04-24

·

Updated

2026-04-25

·

CVE-2025-67259

CVSS v3.1

6.5

Medium

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
Name of the Vulnerable Software and Affected Versions ClassroomIO version 0.1.13
Description Broken Access Control allows an authenticated low-privileged student user to access unauthorized course-level information. By modifying intercepted API requests—specifically changing a captured POST request to a GET request against the '/rest/v1/course' PostgREST endpoint—sensitive data is disclosed. This information includes details of other students, tutor and admin profiles, and internal course metadata.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

Improper Authorization

Improper Access Control

Weakness Enumeration

Related Identifiers

CVE-2025-67259

Affected Products

Classroomio