User Alert - Less Critical - Access Bypass
Project
Date
Severity
Less Critical
Affected versions
<7.x-1.11
The User Alert module contained an Insecure Direct Object Reference (IDOR) vulnerability in its message dismissal endpoint, allowing authenticated users to mark any node as dismissed without proper access control checks.