Description
A command execution vulnerability exists in the default legacy spellchecker plugin in Moodle 3.10. A specially crafted series of HTTP requests can lead to command execution. An attacker must have administrator privileges to exploit this vulnerabilities.
Remediation
References
Related Vulnerabilities
WordPress Plugin Pinterest Automatic Pin Security Bypass (4.14.3)
Oracle JRE CVE-2014-2414 Vulnerability (CVE-2014-2414)
XOOPS Exposure of Sensitive Information to an Unauthorized Actor Vulnerability (CVE-2011-3822)
phpMyAdmin Exposure of Sensitive Information to an Unauthorized Actor Vulnerability (CVE-2015-2206)