Description
Moodle through 2.5.2 allows remote authenticated administrators to execute arbitrary programs by configuring the aspell pathname and then triggering a spell-check operation within the TinyMCE editor.
Remediation
References
Related Vulnerabilities
PHP Deserialization of Untrusted Data Vulnerability (CVE-2017-11143)
PrestaShop Unrestricted Upload of File with Dangerous Type Vulnerability (CVE-2018-19126)
WordPress Plugin BezahlCode-Generator 'gen_name' Parameter Cross-Site Scripting (1.0)
TYPO3 Improper Control of Generation of Code ('Code Injection') Vulnerability (CVE-2014-3942)