Review reviewHigh
CVE-2025-65672
classroomio
Insecure Direct Object Reference (IDOR) in classroomio 0.1.13 allows unauthorized share and invite access to course settings.
- CVSS
- 7.5
- EPSS
- 0.35% 27.3% percentile
- CISA KEV
- Not listed
- Published
- 2025.11.27
Insecure Direct Object Reference (IDOR) in classroomio 0.1.13 allows unauthorized share and invite access to course settings.
The CVSS severity warrants an early asset and exposure review.
Insecure Direct Object Reference (IDOR) in classroomio 0.1.13 allows unauthorized share and invite access to course settings.
Confirm exposure before applying a vendor-supported change.
Confirm that classroomio and an affected version are present.
Combine exploitation signals with asset exposure and business criticality.
Follow the vendor advisory or supported update path and preserve rollback options.
Recheck the version, service health, access paths, and relevant logs.