Description
Separate Groups mode restrictions were not honored when performing a forum export, which would export forum data for all groups. By default this only provided additional access to non-editing teachers.
Remediation
References
Related Vulnerabilities
WordPress Plugin WP Events Calendar 'event_id' Parameter SQL Injection (6.5.2)
WordPress Plugin Ultimate Membership Pro Security Bypass (8.6)
Python Improper Neutralization of CRLF Sequences ('CRLF Injection') Vulnerability (CVE-2019-9740)
Apache HTTP Server Resource Management Errors Vulnerability (CVE-2007-6422)