CVE-2012-2246: Mahara
Medium severity, CVSS 6.8. EPSS: 1.3% chance of exploitation in the next 30 days.
Mahara 1.4.x before 1.4.5 and 1.5.x before 1.5.4 allows remote attackers to conduct clickjacking attacks to delete arbitrary users and bypass CSRF protection via account/delete.php.
Affected products
- Mahara Mahara: version 1.4 only; version 1.4.0 only; version 1.4.1 only; version 1.4.2 only; version 1.4.3 only; version 1.4.4 only; …
Published 2012-11-24. Last modified 2026-06-16.