CVE-2013-3630
Moodle Authenticated Spelling Binary Remote Code Execution
EPSS 42.6%
Description
Moodle through 2.5.2 allows remote authenticated administrators to execute arbitrary programs by configuring the aspell pathname and then triggering a spell-check operation within the TinyMCE editor.
How to fix CVE-2013-3630
To remediate CVE-2013-3630, upgrade the affected package to a fixed version below.
- Packagist/moodle/moodle—upgrade to 2.5.3 or later
Is CVE-2013-3630 being exploited?
Moderate — EPSS is 42.6%. Track this CVE but it's not at the top of the prioritisation list.
Affected packages (1)
- from 0, < 2.5.3