Description
Separate Groups mode restrictions were not honored when performing a forum export, which would export forum data for all groups. By default this only provided additional access to non-editing teachers.
Remediation
References
Related Vulnerabilities
WordPress Plugin BAVOKO SEO Tools-All-in-One WordPress SEO Security Bypass (2.1.9.7)
WordPress Plugin Page Restrict Cross-Site Scripting (2.2.1)
e107 Unrestricted Upload of File with Dangerous Type Vulnerability (CVE-2018-16388)
Moodle Improper Control of Generation of Code ('Code Injection') Vulnerability (CVE-2013-5674)