CVE-2012-2244: Mahara
Medium severity, CVSS 6.0. EPSS: 1.7% chance of exploitation in the next 30 days.
Mahara 1.4.x before 1.4.5 and 1.5.x before 1.5.4 allows remote authenticated administrators to execute arbitrary programs by modifying the path to clamav. NOTE: this can be exploited without authentication by leveraging CVE-2012-2243.
Affected products
- Mahara Mahara: version 1.4 only; version 1.4.0 only; version 1.4.1 only; version 1.4.2 only; version 1.4.3 only; version 1.5 only; …
Published 2012-11-24. Last modified 2026-06-16.