PT-2026-95022 · Scoold · Scoold
CVSS v3.1
6.5
Medium
| Vector | AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N |
Name of the Vulnerable Software and Affected Versions
Scoold versions prior to 1.69.0
Description
Users with personal API tokens can retrieve replies from questions in private spaces they are not authorized to access. This occurs because the
getPostReplies() function in ApiController.java fails to apply the canAccessSpace check before returning data from the 'GET /api/posts/{id}/answers' endpoint. The issue is exploitable when scoold.api user access enabled and scoold.api enabled are set to true and a token holder identifies or enumerates a private question identifier. Consequently, while the question endpoint may deny access, the answers endpoint returns private reply bodies, exposing confidential team or project discussions.Recommendations
Update to version 1.69.0.
As a temporary mitigation, set
scoold.api user access enabled or scoold.api enabled to false to disable API access.Exploit
Fix
Missing Authorization
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Scoold