An Insecure Direct Object Reference (IDOR) in the /dashboard/notes endpoint of Syaqui Collegetivity v1.0.0 allows attackers to impersonate other users and perform arbitrary operations via a crafted POST request.
| Software | From | Fixed in |
|---|---|---|
| syauqi / collegetivity | 1.0.0 | 1.0.0.x |