Home
MEDIUM: 5.4 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:L/I:L/A:NDefault status
unknown
5.1.2.1763770643 (custom)
affected
Description
A client-side authorization flaw in Lightspeed Classroom v5.1.2.1763770643 allows unauthenticated attackers to impersonate users by bypassing integrity checks and abusing client-generated authorization tokens, leading to unauthorized control and monitoring of student devices.
Problem types
CWE-863 Incorrect Authorization
Product status
5.1.2.1763770643 (custom)
References
tasty-hovercraft-9b9.notion.site/...5b4a800c9eefc5526479820a
www.incognitotgt.me/blog/lightspeed