Impact
A client-side authorization flaw in Lightspeed Systems Classroom v5.1.2.1763770643 allows unauthenticated attackers to impersonate users by bypassing integrity checks and abusing client-generated authorization tokens, leading to unauthorized control and monitoring of student devices.
Affected Systems
The vulnerability affects Lightspeed Classroom version 5.1.2.1763770643. No other versions or products are listed at this time.
Risk and Exploitability
The CVSS score of 5.4 indicates a moderate severity. The EPSS score of less than 1% suggests a very low likelihood of exploitation, and the vulnerability is not listed in the CISA KEV catalog. The attack vector is client‑side; the flaw can likely be exercised by any entity able to interact with the Classroom client, whether by providing forged tokens or by directly accessing the client’s network endpoints. Detailed exploitation steps are not supplied in the advisory, but the description implies that an attacker can impersonate a user without needing prior authentication.
OpenCVE Enrichment