Executive brief
Scoold, a knowledge-sharing and Q&A platform for teams, contains a flaw that allows any logged-in user to overwrite questions posted by others. By simply providing the ID of an existing question when posting a new one, an attacker can replace legitimate content with their own. This can lead to the defacement of important company knowledge, loss of original discussion data, and the spread of misinformation within a team's internal documentation.
Technical details
An authorization bypass (CWE-639) exists in the `QuestionsController.java` component of Scoold. The application's question creation handler (`POST /questions/ask`) accepts an optional `postId` parameter from the client; if provided, the application uses this ID for the new post without verifying if it is already in use or owned by another user. Because question IDs are exposed in public URLs, an authenticated attacker can capture a victim's question ID and submit a request that overwrites the original content while maintaining the original ID. This results in the loss of integrity for the question's title and body, though existing comments and replies remain attached to the now-modified thread. The vulnerability is fixed in version 1.66.2.
Affected products
- Erudika Scoold < 1.66.2
Timeline
- 2026-04-06: advisory: Vendor advisory published on GitHub
- 2026-04-07: disclosed: CVE-2026-39354 published
- 2026-04-07: patched: Fix released in version 1.66.2