In Mahara 18.10 before 18.10.5, 19.04 before 19.04.4, and 19.10 before 19.10.2, certain personal information is discoverable inspecting network responses on the 'Edit access' screen when sharing portfolios.
"https://storage.googleapis.com/osv-test-cve-osv-conversion/osv-output/CVE-2020-9282.json"