it's possible to perform a privilege escalation attack due to a lack
of permissions check in the group creation process. A malicious user
could exploit this vulnerability to take control of every group
(change name, description, avatar and settings).
To exploit this vulnerability you have to follow these steps:
1) Create a cookie named bp_new_group_id=<id_of_victim_group>
2) Visit the url http://example.com/groups/create/step/group-details/
3) Enjoy the power
-Pietro Oliva-