In Montala ResourceSpace through 9.8 before r19636, csv_export_results_metadata.php allows attackers to export collection metadata via a non-NULL k value.
id: CVE-2022-31260
info:
name: ResourceSpace - Metadata Export
author: ritikchaddha
severity:
...