Moodle Authorization Bypass Through User-Controlled Key Vulnerability (CVE-2024-25983)
Description
Insufficient checks in a web service made it possible to add comments to the comments block on another user's dashboard when it was not otherwise available (e.g., on their profile page).