Impact
Scoold allows authenticated users who are not members of a private space to post replies and comments on questions belonging to that space because the authorization check used by the read path is omitted from the reply and comment creation controllers. As a result, an attacker with a valid session can create or modify content in a private discussion that they cannot normally view, and the system may send notifications that expose the presence or details of those private interactions. This is an instance of an authorization bypass (CWE‑862).
Affected Systems
The vulnerability exists in all releases of Erudika Scoold prior to version 1.69.0. Users who run older builds with private spaces enabled (and scoold.is_default_space_public set to false) are susceptible.
Risk and Exploitability
The CVSS score of 6.5 indicates medium severity. The EPSS score of less than 1 % suggests a low likelihood of exploitation at this time, and the vulnerability is not listed in CISA’s KEV catalog. An attacker would need an authenticated session and the ID of a question within a private space, which can typically be enumerated or guessed. Once these conditions are met, the attacker can post arbitrary replies and comments that will be stored and potentially generate notifications revealing the existence or content of private discussions. Overall, the risk is moderate, with the primary concern being the inadvertent disclosure of private information.
OpenCVE Enrichment