Описание
Moodle through 2.5.2 allows remote authenticated administrators to execute arbitrary programs by configuring the aspell pathname and then triggering a spell-check operation within the TinyMCE editor.
Примечания
For Moodle: Not a securiy issue according to upstream, only applicable to administrators, see bug #775842
https://tracker.moodle.org/browse/MDL-41449
https://community.rapid7.com/community/metasploit/blog/2013/10/30/seven-tricks-and-treats
EPSS
Связанные уязвимости
Moodle through 2.5.2 allows remote authenticated administrators to execute arbitrary programs by configuring the aspell pathname and then triggering a spell-check operation within the TinyMCE editor.
Moodle through 2.5.2 allows remote authenticated administrators to execute arbitrary programs by configuring the aspell pathname and then triggering a spell-check operation within the TinyMCE editor.
Moodle Authenticated Spelling Binary Remote Code Execution
EPSS