GHSA-mh75-3225-9wcj: An Insecure Direct Object Reference (IDOR) in classroomio 0.1.13 allows students to access...

Important cybersecurity news update

An Insecure Direct Object Reference (IDOR) in classroomio 0.1.13 allows students to access sensitive admin/teacher endpoints by manipulating course IDs in URLs, resulting in unauthorized disclosure of sensitive course, admin, and student data. The leak occurs momentarily before the system reverts to a normal state restricting access.