The UUID Wasn't Secret
SecureLearn replaced sequential profile IDs with UUIDs and assumes that makes records impossible to discover. Your own profile uses a UUID, but another feature exposes UUID references for students. Determine whether possession of a leaked UUID is enough to cross the authorization boundary.
Objective
Find another student's UUID through a separate application feature, reuse it on the profile route, and recover the flag.