CVE-2013-3630
Moodle Authenticated Spelling Binary Remote Code Execution
EPSS 42.6%
描述
Moodle through 2.5.2 allows remote authenticated administrators to execute arbitrary programs by configuring the aspell pathname and then triggering a spell-check operation within the TinyMCE editor.
如何修補 CVE-2013-3630
要修補 CVE-2013-3630,請將受影響套件升級到下列已修補版本。
- Packagist/moodle/moodle—升級至 2.5.3 或更新版本
CVE-2013-3630 正在被利用嗎?
中等 — EPSS 為 42.6%,可持續追蹤但非最高優先。
受影響套件(1)
- from 0, < 2.5.3