Insufficient checks in a web service made it possible to add comments to the comments block on another user's dashboard when it was not otherwise available (e.g., on their profile page).
The system's authorization functionality does not prevent one user from gaining access to another user's data or record by modifying the key value identifying the data.