DescriptionMoodle through 2.5.2 allows remote authenticated administrators to execute arbitrary programs by configuring the aspell pathname and then triggering a spell-check operation within the TinyMCE editor.
NVD severitymedium


For Moodle: Not a securiy issue according to upstream, only applicable to administrators, see bug #775842

