{"id":"CVE-2013-3630","aliases":[],"url":"https://o3.security/vulnerability/CVE-2013-3630","summary":"Moodle  Authenticated Spelling Binary Remote Code Execution","details":"Moodle through 2.5.2 allows remote authenticated administrators to execute arbitrary programs by configuring the aspell pathname and then triggering a spell-check operation within the TinyMCE editor.","published":"2022-05-13T01:05:39Z","modified":"2024-12-02T05:46:46.269302Z","cvss":null,"epss":{"score":0.42566,"percentile":0.98602,"asOf":"2026-08-22"},"cisaKev":null,"exploitsKnown":4,"affectedPackages":[{"ecosystem":"Packagist","name":"moodle/moodle","fixedVersion":"2.5.3"}],"fix":null,"references":[{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2013-3630"},{"type":"WEB","url":"https://community.rapid7.com/community/metasploit/blog/2013/10/30/seven-foss-disclosures-part-one"},{"type":"WEB","url":"https://community.rapid7.com/community/metasploit/blog/2013/10/30/seven-tricks-and-treats"},{"type":"PACKAGE","url":"https://github.com/moodle/moodle"},{"type":"WEB","url":"http://packetstormsecurity.com/files/164479/Moodle-Authenticated-Spelling-Binary-Remote-Code-Execution.html"}],"provenance":{"sources":["OSV.dev","FIRST.org (EPSS)"],"lastVerified":"2024-12-02T05:46:46.269302Z"}}