CVE-2025-67298

An issue in ClasroomIO before v.0.2.6 allows a remote attacker to escalate privileges via the endpoints /api/verify and /rest/v1/profile
Configurations

Configuration 1 (hide)

cpe:2.3:a:classroomio:classroomio:*:*:*:*:*:*:*:*

History

07 Apr 2026, 01:19

Type Values Removed Values Added
First Time Classroomio
Classroomio classroomio
CPE cpe:2.3:a:classroomio:classroomio:*:*:*:*:*:*:*:*
References () https://gist.github.com/prashunbaral/70c4f6f9d9ff8b82295623073eb41f3a - () https://gist.github.com/prashunbaral/70c4f6f9d9ff8b82295623073eb41f3a - Exploit, Third Party Advisory
References () https://github.com/classroomio/classroomio/releases/tag/v0.2.6 - () https://github.com/classroomio/classroomio/releases/tag/v0.2.6 - Release Notes
Summary
  • (es) Un problema en ClasroomIO antes de la v.0.2.6 permite a un atacante remoto escalar privilegios a través de los endpoints /api/verify y /rest/v1/profile

11 Mar 2026, 16:16

Type Values Removed Values Added
CWE CWE-290
CWE-345
CWE-639
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 8.1

11 Mar 2026, 15:16

Type Values Removed Values Added
New CVE

Information

Published : 2026-03-11 15:16

Updated : 2026-04-07 01:19


NVD link : CVE-2025-67298

Mitre link : CVE-2025-67298

CVE.ORG link : CVE-2025-67298


JSON object : View

Products Affected

classroomio

  • classroomio
CWE
CWE-290

Authentication Bypass by Spoofing

CWE-345

Insufficient Verification of Data Authenticity

CWE-639

Authorization Bypass Through User-Controlled Key