cvedb.io
CVE-2026-34832
MEDIUM · CVSS 6.5
EPSS exploitation probability: 0%
Published 2026-04-02T20:16:27.040 · Last modified 2026-06-17T10:39:42.677

Summary

Scoold is a Q&A and a knowledge sharing platform for teams. Prior to version 1.66.1, Scoold contains an authenticated authorization flaw in feedback deletion that allows any logged-in, low-privilege user to delete another user's feedback post by submitting its ID to POST /feedback/{id}/delete. The handler enforces authentication but does not enforce object ownership (or moderator/admin authorization) before deletion. In verification, a second non-privileged account successfully deleted a victim account's feedback item, and the item immediately disappeared from the feedback listing/detail views. This issue has been patched in version 1.66.1.

Affected products

erudika — scoold

Does this affect you?

Add your gear to cvedb and we'll alert you only when erudika ships something exploited.

Check my exposure →

References

This product uses data from the NVD API but is not endorsed or certified by the NVD. Informational only; not professional security advice.