PT-2026-30976 · Scoold · Scoold

·

CVE-2026-39354

·

Published

2026-04-07

·

Updated

2026-04-07

CVSS v3.1

6.5

Medium

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N
Name of the Vulnerable Software and Affected Versions Scoold versions prior to 1.66.2
Description A flaw in Scoold allows any logged-in, low-privilege user to overwrite another user's existing question. This is achieved by supplying the question's public ID as the postId parameter to the POST request at the ''/questions/ask'' API endpoint. Question IDs are exposed in normal question URLs, enabling an attacker to take a victim question ID from a public page and replace the existing content with attacker-controlled content. This results in a loss of integrity of user-generated content and corrupts the discussion thread.
Recommendations Update to version 1.66.2 or later.

Exploit

Fix

IDOR

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-39354
GHSA-768R-CV9P-WRCM

Affected Products

Scoold