
An issue was discovered in classroomio 0.1.13. Student accounts are able to delete courses from the Explore page without any authorization or authentication checks, bypassing the expected admin-only deletion restriction. Discovered by - Rivek Raj Tamang (RivuDon), Sikkim, India.
An issue was discovered in classroomio 0.1.13. Student accounts are able to delete courses from the Explore page without any authorization or authentication checks, bypassing the expected admin-only deletion restriction. Discovered by - Rivek Raj Tamang (RivuDon), Sikkim, India.
Affected Product: ClassroomIO
Broken Access Control
A Broken Access Control vulnerability in ClassroomIO 0.1.13 allows student-level users to delete published courses without any authorization checks. The “Delete Course” action—intended exclusively for administrators—is improperly exposed on the Explore page, enabling any authenticated student to remove entire courses created by admins. This flaw results in unauthorized data manipulation, loss of learning content, and disruption of platform functionality. The issue stems from missing server-side permission validation, allowing students to bypass role restrictions simply by interacting with the exposed deletion endpoint.
Have two accounts Admin (Chromium) and Student (Firefox)
Login as Admin
Login as Student
Student navigates to the Explore page and sees the newly published course.
Student has the option to delete
Clicks the "Delete" button available alongside the course. Student confirms the deletion.
Course gets deleted without requiring any authentication or authorization approval.
Login as Admin
This vulnerability was discovered and responsibly reported by:
Rivek Raj Tamang (RivuDon) from Sikkim, India