CVE-2012-2239: Debian Linux
Critical severity, CVSS 9.1. EPSS: 1.6% chance of exploitation in the next 30 days.
Mahara 1.4.x before 1.4.4 and 1.5.x before 1.5.3 allows remote attackers to read arbitrary files or create TCP connections via an XML external entity (XXE) injection attack, as demonstrated by reading config.php.
Affected products
- Debian Debian Linux: version 6.0 only
- Mahara Mahara: from 1.4.0, before 1.4.4 (fixed in 1.4.4); from 1.5.0, before 1.5.3 (fixed in 1.5.3)
Published 2012-11-24. Last modified 2026-06-16.