Description Insufficient capability checks made it possible for teachers to download users outside of their courses. Remediation References CVE-2021-40692 Related Vulnerabilities Zope Web Application Server Improper Neutralization of Input During Web Page Generation (Cross-site Scripting) (CVE-2021-33507) WordPress Plugin Contact Form 7 Style Cross-Site Request Forgery (3.2) IBM RTC Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Vulnerability (CVE-2021-20350) WordPress Plugin dsIDXpress IDX Multiple Unspecified Vulnerabilities (2.1.32) PHP Improper Input Validation Vulnerability (CVE-2015-4605) Severity Medium Classification CVE-2021-40692 CWE-863 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N Tags Missing Update Known Vulnerabilities