Executive brief
ClassroomIO is an open-source education platform used by companies as an alternative to learning management systems like Moodle. A security flaw allows students to view sensitive administrative information, such as attendance records, student grades, and course analytics, by simply modifying the web address in their browser. This could lead to the unauthorized disclosure of private student data and internal course management details.
Technical details
An Insecure Direct Object Reference (IDOR) vulnerability exists in classroomio version 0.1.13 due to missing authorization checks on administrative endpoints. A student-level user can bypass intended access controls by manually crafting URLs and substituting course IDs to reach privileged paths such as /analytics, /attendance, /submissions, /people, and /marks. While the system reportedly reverts to a restricted state shortly after the initial request, the flaw allows for the momentary disclosure of sensitive course, admin, and student data. The attack is performed over the network and requires a low-privileged student account but no user interaction.
Affected products
- classroomio classroomio 0.1.13
Timeline
- 2025-11-26: disclosed
- 2025-11-26: advisory