CVE-2012-2246
medium
CVSS v3
—
CVSS v2
6.8
VIR risk
6.8
Description
Mahara 1.4.x before 1.4.5 and 1.5.x before 1.5.4 allows remote attackers to conduct clickjacking attacks to delete arbitrary users and bypass CSRF protection via account/delete.php.
Predictions
Exploit likelihood
20%
Patch ETA
—
Heuristic predictions, AS-IS, for prioritization only.
Mitigations
Vendor advisory: security@debian.org — https://mahara.org/interaction/forum/topic.php?id=4939
References
- http://www.debian.org/security/2012/dsa-2591
- https://bugs.launchpad.net/mahara/+bug/1057240
- https://exchange.xforce.ibmcloud.com/vulnerabilities/79273
- https://mahara.org/interaction/forum/topic.php?id=4939
- http://www.debian.org/security/2012/dsa-2591
- https://bugs.launchpad.net/mahara/+bug/1057240
- https://exchange.xforce.ibmcloud.com/vulnerabilities/79273
- https://mahara.org/interaction/forum/topic.php?id=4939
CWEs
CWE-20
Verify integrity in audit chain (admin only). AS-IS.