Description
Teachers exporting a forum in CSV format could receive a CSV of forums from all courses in some circumstances. Moodle versions 3.10 to 3.10.3, 3.9 to 3.9.6 and 3.8 to 3.8.8 are affected.
Remediation
References
Related Vulnerabilities
Jboss EAP Use of a Broken or Risky Cryptographic Algorithm Vulnerability (CVE-2011-2487)
phpMyAdmin Permissions, Privileges, and Access Controls Vulnerability (CVE-2016-9849)
ownCloud Cross-Site Request Forgery (CSRF) Vulnerability (CVE-2013-0300)