An issue in ClasroomIO before v.0.2.6 allows a remote attacker to escalate privileges via the endpoints /api/verify and /rest/v1/profile
References
| Link | Resource |
|---|---|
| https://gist.github.com/prashunbaral/70c4f6f9d9ff8b82295623073eb41f3a | Exploit Third Party Advisory |
| https://github.com/classroomio/classroomio/releases/tag/v0.2.6 | Release Notes |
Configurations
History
07 Apr 2026, 01:19
| Type | Values Removed | Values Added |
|---|---|---|
| First Time |
Classroomio
Classroomio classroomio |
|
| CPE | cpe:2.3:a:classroomio:classroomio:*:*:*:*:*:*:*:* | |
| References | () https://gist.github.com/prashunbaral/70c4f6f9d9ff8b82295623073eb41f3a - Exploit, Third Party Advisory | |
| References | () https://github.com/classroomio/classroomio/releases/tag/v0.2.6 - Release Notes | |
| Summary |
|
11 Mar 2026, 16:16
| Type | Values Removed | Values Added |
|---|---|---|
| CWE | CWE-290 CWE-345 CWE-639 |
|
| CVSS |
v2 : v3 : |
v2 : unknown
v3 : 8.1 |
11 Mar 2026, 15:16
| Type | Values Removed | Values Added |
|---|---|---|
| New CVE |
Information
Published : 2026-03-11 15:16
Updated : 2026-04-07 01:19
NVD link : CVE-2025-67298
Mitre link : CVE-2025-67298
CVE.ORG link : CVE-2025-67298
JSON object : View
Products Affected
classroomio
- classroomio
