An issue in ClasroomIO before v.0.2.6 allows a remote attacker to escalate privileges via the endpoints /api/verify and /rest/v1/profile
{ "versions": [ { "introduced": "0" }, { "fixed": "v.0.2.6" } ] }
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2025-67298.json"