Description
The Scratch Channel is a news website. If the user makes a fork, they can change the admins and make an article. Since the API uses a POST request, it will make an article. This issue is fixed in v1.2.
Problem types
CWE-862: Missing Authorization
Product status
References
github.com/...client/security/advisories/GHSA-775w-g375-pjff