Back

MEDIUM

An Insecure Direct Object Reference (IDOR) in classroomio 0.1.13 allows students to access sensitive admin/teacher endpoints by manipulating course IDs in URLs, resulting in unauthorized disclosure of sensitive course, admin, and student data

Published Nov 26, 2025

Description

An Insecure Direct Object Reference (IDOR) in classroomio 0.1.13 allows students to access sensitive admin/teacher endpoints by manipulating course IDs in URLs, resulting in unauthorized disclosure of sensitive course, admin, and student data. The leak occurs momentarily before the system reverts to a normal state restricting access.

Affected products

Remediation

No remediation recorded yet.

References (3)

Change history (0)

No recorded changes yet.

Sources

CVE.org / MITRE

Status PUBLISHED
Assigner mitre
Published Nov 26, 2025
Updated Jul 5, 2026
Reserved Nov 18, 2025

CISA Vulnrichment

Updated Nov 28, 2025

NVD

Status Modified
Modified Jul 5, 2026

Red Hat

No data

ENISA EUVD

Assigner mitre
Published Nov 26, 2025
Updated Jul 5, 2026

GitHub

No data