Loading HuntDB...

GHSA-c7jj-vfmr-j9mj

GitHub Security Advisory

Moodle command execution vulnerability exists in the default legacy spellchecker plugin

✓ GitHub Reviewed CRITICAL Has CVE

Advisory Details

A command execution vulnerability exists in the default legacy spellchecker plugin in a few Moodle multiple specific versions. A specially crafted series of HTTP requests can lead to command execution. An attacker must have administrator privileges to exploit this vulnerabilities.

Affected Packages

Packagist moodle/moodle
Packagist moodle/moodle
Packagist moodle/moodle

Related CVEs

Key Information

GHSA ID
GHSA-c7jj-vfmr-j9mj
Published
May 24, 2022 7:06 PM
Last Modified
April 24, 2024 5:29 PM
CVSS Score
9.0 /10
Primary Ecosystem
Packagist
Primary Package
moodle/moodle
GitHub Reviewed
✓ Yes

Dataset

Last updated: June 15, 2025 6:24 AM

Data from GitHub Advisory Database. This information is provided for research and educational purposes.