GHSA-fv9m-8cwh-9rgjMediumCVSS 5.4
A client-side authorization flaw in Lightspeed Classroom v5.1.2.1763770643 allows unauthenticated...
🔗 CVE IDs covered (1)
📋 Description
A client-side authorization flaw in Lightspeed Classroom v5.1.2.1763770643 allows unauthenticated attackers to impersonate users by bypassing integrity checks and abusing client-generated authorization tokens, leading to unauthorized control and monitoring of student devices.
🔗 References (7)
- https://nvd.nist.gov/vuln/detail/CVE-2026-30368
- https://tasty-hovercraft-9b9.notion.site/Enabling-Unauthorized-Remote-Control-of-Student-Devices-with-Lightspeed-Classroom-2ec5157f5b4a800c9eefc5526479820a
- https://www.incognitotgt.me/blog/lightspeed
- https://github.com/truekas/ls-poc
- https://truekas.dev/blog/lightspeed
- https://www.lightspeedsystems.com/products/lightspeed-classroom-management
- https://github.com/advisories/GHSA-fv9m-8cwh-9rgj