Description
A command execution vulnerability exists in the default legacy spellchecker plugin in Moodle 3.10. A specially crafted series of HTTP requests can lead to command execution. An attacker must have administrator privileges to exploit this vulnerabilities.
Remediation
References
Related Vulnerabilities
Oracle Database Server CVE-2008-2604 Vulnerability (CVE-2008-2604)
WordPress Exposure of Sensitive Information to an Unauthorized Actor Vulnerability (CVE-2013-2202)
WordPress Plugin Connections Business Directory Cross-Site Scripting (8.5.8)
ownCloud Improper Control of Generation of Code ('Code Injection') Vulnerability (CVE-2014-2051)