Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-fx5h-3786-h2w6

Опубликовано: 13 мая 2022
Источник: github
Github: Прошло ревью

Описание

PHP Spellchecker addon for TinyMCE allows attackers to trigger arbitrary outbound HTTP requests

classes/GoogleSpell.php in the PHP Spellchecker (aka Google Spellchecker) addon before 2.0.6.1 for TinyMCE, as used in Moodle 2.1.x before 2.1.10, 2.2.x before 2.2.7, 2.3.x before 2.3.4, and 2.4.x before 2.4.1 and other products, does not properly handle control characters, which allows remote attackers to trigger arbitrary outbound HTTP requests via a crafted string.

Пакеты

Наименование

moodle/moodle

composer
Затронутые версииВерсия исправления

>= 2.1.0, < 2.1.10

2.1.10

Наименование

moodle/moodle

composer
Затронутые версииВерсия исправления

>= 2.2.0, < 2.2.7

2.2.7

Наименование

moodle/moodle

composer
Затронутые версииВерсия исправления

>= 2.3.0, < 2.3.4

2.3.4

Наименование

moodle/moodle

composer
Затронутые версииВерсия исправления

= 2.4.0

2.4.1

EPSS

Процентиль: 68%
0.006
Низкий

Связанные уязвимости

ubuntu
больше 12 лет назад

classes/GoogleSpell.php in the PHP Spellchecker (aka Google Spellchecker) addon before 2.0.6.1 for TinyMCE, as used in Moodle 2.1.x before 2.1.10, 2.2.x before 2.2.7, 2.3.x before 2.3.4, and 2.4.x before 2.4.1 and other products, does not properly handle control characters, which allows remote attackers to trigger arbitrary outbound HTTP requests via a crafted string.

nvd
больше 12 лет назад

classes/GoogleSpell.php in the PHP Spellchecker (aka Google Spellchecker) addon before 2.0.6.1 for TinyMCE, as used in Moodle 2.1.x before 2.1.10, 2.2.x before 2.2.7, 2.3.x before 2.3.4, and 2.4.x before 2.4.1 and other products, does not properly handle control characters, which allows remote attackers to trigger arbitrary outbound HTTP requests via a crafted string.

debian
больше 12 лет назад

classes/GoogleSpell.php in the PHP Spellchecker (aka Google Spellcheck ...

EPSS

Процентиль: 68%
0.006
Низкий