Vulnerability Description
A Broken Access Control vulnerability exists in ClassroomIO v0.1.13 where an authenticated low-privileged "student" user can access unauthorized course-level information by modifying intercepted API requests. Changing a captured POST request to a GET request against the /rest/v1/course PostgREST endpoint results in disclosure of sensitive information including other students details, tutor/admin profiles, and internal course metadata.
CVSS Score
MEDIUM
Related Weaknesses (CWE)
References
- https://drive.google.com/file/d/1G_IjEURNBcaSmBo4FdOo_27q-4H9MV34/view?usp=drive
- https://github.com/classroomio/classroomio/issues/642
- https://github.com/classroomio/classroomio/issues/642
FAQ
What is CVE-2025-67259?
CVE-2025-67259 is a vulnerability with a CVSS score of 6.5 (MEDIUM). A Broken Access Control vulnerability exists in ClassroomIO v0.1.13 where an authenticated low-privileged "student" user can access unauthorized course-level information by modifying intercepted API r...
How severe is CVE-2025-67259?
CVE-2025-67259 has been rated MEDIUM with a CVSS base score of 6.5/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2025-67259?
Check the references section above for vendor advisories and patch information. Review vendor security bulletins for remediation guidance.