Moodle Improper Control of Generation of Code (Code Injection) Vulnerability - CVE-2013-3630 - Vulnerability Database

Moodle Improper Control of Generation of Code (Code Injection) Vulnerability - CVE-2013-3630

Medium
Reference: CVE-2013-3630
Title: Moodle Improper Control of Generation of Code (Code Injection) Vulnerability
Overview:

Moodle through 2.5.2 allows remote authenticated administrators to execute arbitrary programs by configuring the aspell pathname and then triggering a spell-check operation within the TinyMCE editor.