GHSA-c7jj-vfmr-j9mj
Dashboard / Vulnerabilities / GHSA-c7jj-vfmr-j9mj
GHSA-c7jj-vfmr-j9mj
Summary: Moodle command execution vulnerability exists in the default legacy spellchecker plugin
Details: A command execution vulnerability exists in the default legacy spellchecker plugin in a few Moodle multiple specific versions. A specially crafted series of HTTP requests can lead to command execution. An attacker must have administrator privileges to exploit this vulnerabilities.
References: https://nvd.nist.gov/vuln/detail/CVE-2021-21809, https://github.com/moodle/moodle, https://talosintelligence.com/vulnerability_reports/TALOS-2021-1277, http://packetstormsecurity.com/files/164481/Moodle-SpellChecker-Path-Authenticated-Remote-Command-Execution.html
Affected packages
Package
Name: moodle/moodle
Purl: pkg:composer/moodle/moodle
Affected ranges
Type: N/A
Events:
