The comment module allows users to leave comments on content on the site.
The module supports unpublishing comments by privileged users. Users with the "post comments without approval" permission however could craft a URL which allows them to republish previously unpublished comments.
Vendor Status:
Drupal issued an update for this vulnerability