CVE-2025-65670: n/a
An Insecure Direct Object Reference (IDOR) in classroomio 0.1.13 allows students to access sensitive admin/teacher endpoints by manipulating course IDs in URLs, resulting in unauthorized disclosure of sensitive course, admin, and student data. The leak occurs momentarily before the system reverts to a normal state restricting access.
AI Analysis
Technical Summary
This vulnerability in classroomio 0.1.13 involves an IDOR flaw (CWE-639) where insufficient access control on course ID parameters in URLs enables students with limited privileges to access restricted admin and teacher endpoints. This results in unauthorized disclosure of sensitive information related to courses, administrators, and students. The exposure is momentary before the system restores proper access controls. No known exploits are reported in the wild, and no patch or official fix has been documented.
Potential Impact
Unauthorized users (students) can temporarily access sensitive administrative and teacher data by manipulating course ID parameters. This leads to confidentiality breaches of course, admin, and student information. There is no indication of integrity or availability impact. The exposure is transient, as the system reverts to normal access restrictions shortly after the unauthorized access.
Mitigation Recommendations
Patch status is not yet confirmed — check the vendor advisory for current remediation guidance. Until a fix is available, restrict access to the affected version 0.1.13 and monitor for suspicious URL parameter manipulation. Implement additional access control checks on server-side to validate user permissions for requested resources.
CVE-2025-65670: n/a
Description
An Insecure Direct Object Reference (IDOR) in classroomio 0.1.13 allows students to access sensitive admin/teacher endpoints by manipulating course IDs in URLs, resulting in unauthorized disclosure of sensitive course, admin, and student data. The leak occurs momentarily before the system reverts to a normal state restricting access.
CVSS v3.1
Score 4.3medium
Affected software
pkg:github/classroomio/classroomioRun on your own infrastructure? Check whether these packages are installed with threat-finder — our free open-source scanner.
Weaknesses
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
This vulnerability in classroomio 0.1.13 involves an IDOR flaw (CWE-639) where insufficient access control on course ID parameters in URLs enables students with limited privileges to access restricted admin and teacher endpoints. This results in unauthorized disclosure of sensitive information related to courses, administrators, and students. The exposure is momentary before the system restores proper access controls. No known exploits are reported in the wild, and no patch or official fix has been documented.
Potential Impact
Unauthorized users (students) can temporarily access sensitive administrative and teacher data by manipulating course ID parameters. This leads to confidentiality breaches of course, admin, and student information. There is no indication of integrity or availability impact. The exposure is transient, as the system reverts to normal access restrictions shortly after the unauthorized access.
Mitigation Recommendations
Patch status is not yet confirmed — check the vendor advisory for current remediation guidance. Until a fix is available, restrict access to the affected version 0.1.13 and monitor for suspicious URL parameter manipulation. Implement additional access control checks on server-side to validate user permissions for requested resources.
Technical Details
- Data Version
- 5.2
- Assigner Short Name
- mitre
- Date Reserved
- 2025-11-18T00:00:00.000Z
- State
- PUBLISHED
Threat ID: 69275cdeea1ddeeb60e50d0f
Added to database: 11/26/2025, 20:02:38 UTC
Last enriched: 07/05/2026, 21:39:03 UTC
Last updated: 09/10/2026, 19:24:57 UTC
Views: 184
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.