Moodle Authorization Bypass Through User-Controlled Key Vulnerability - CVE-2024-25983 - Vulnerability Database

Moodle Authorization Bypass Through User-Controlled Key Vulnerability - CVE-2024-25983

Medium
Reference: CVE-2024-25983
Title: Moodle Authorization Bypass Through User-Controlled Key Vulnerability
Overview:

Insufficient checks in a web service made it possible to add comments to the comments block on another user39s dashboard when it was not otherwise available (e.g. on their profile page).