MEDIUM
Erudika
CVE published 2026-04-07
CVE-2026-39354
CVE-2026-39354 is an authenticated authorization flaw in Scoold, a Q&A and knowledge sharing platform for teams. Prior to version 1.66.2, a low-privilege user can overwrite another user's existing question by supplying the public ID of that question as the postId parameter in a POST /questions/ask request. This is possible because question IDs are exposed in normal question URLs. As a result, an attacker [truncated]