CVE-2012-6112
Severity CVSS v4.0:
Pending analysis
Type:
CWE-264
Permissions, Privileges, and Access Control
Publication date:
27/01/2013
Last modified:
11/04/2025
Description
classes/GoogleSpell.php in the PHP Spellchecker (aka Google Spellchecker) addon before 2.0.6.1 for TinyMCE, as used in Moodle 2.1.x before 2.1.10, 2.2.x before 2.2.7, 2.3.x before 2.3.4, and 2.4.x before 2.4.1 and other products, does not properly handle control characters, which allows remote attackers to trigger arbitrary outbound HTTP requests via a crafted string.
Impact
Base Score 2.0
5.00
Severity 2.0
MEDIUM
Vulnerable products and versions
| CPE | From | Up to |
|---|---|---|
| cpe:2.3:a:tinymce:spellchecker_php:2.0:*:*:*:*:*:*:* | ||
| cpe:2.3:a:tinymce:spellchecker_php:2.0:a1:*:*:*:*:*:* | ||
| cpe:2.3:a:tinymce:spellchecker_php:2.0:a2:*:*:*:*:*:* | ||
| cpe:2.3:a:tinymce:spellchecker_php:2.0:b1:*:*:*:*:*:* | ||
| cpe:2.3:a:tinymce:spellchecker_php:2.0:b2:*:*:*:*:*:* | ||
| cpe:2.3:a:tinymce:spellchecker_php:2.0:b3:*:*:*:*:*:* | ||
| cpe:2.3:a:tinymce:spellchecker_php:2.0:rc1:*:*:*:*:*:* | ||
| cpe:2.3:a:tinymce:spellchecker_php:2.0.1:*:*:*:*:*:*:* | ||
| cpe:2.3:a:tinymce:spellchecker_php:2.0.2:*:*:*:*:*:*:* | ||
| cpe:2.3:a:tinymce:spellchecker_php:2.0.3:*:*:*:*:*:*:* | ||
| cpe:2.3:a:tinymce:spellchecker_php:2.0.6:*:*:*:*:*:*:* | ||
| cpe:2.3:a:moodle:moodle:2.1.0:*:*:*:*:*:*:* | ||
| cpe:2.3:a:moodle:moodle:2.1.1:*:*:*:*:*:*:* | ||
| cpe:2.3:a:moodle:moodle:2.1.2:*:*:*:*:*:*:* | ||
| cpe:2.3:a:moodle:moodle:2.1.3:*:*:*:*:*:*:* |
To consult the complete list of CPE names with products and versions, see this page
References to Advisories, Solutions, and Tools
- http://git.moodle.org/gw?p=moodle.git&a=search&h=HEAD&st=commit&s=MDL-37283
- http://openwall.com/lists/oss-security/2013/01/21/1
- http://www.tinymce.com/develop/changelog/?type=phpspell
- http://www.tinymce.com/forum/viewtopic.php?id=30036
- https://github.com/tinymce/tinymce_spellchecker_php/commit/22910187bfb9edae90c26e10100d8145b505b974
- https://moodle.org/mod/forum/discuss.php?d=220157
- http://git.moodle.org/gw?p=moodle.git&a=search&h=HEAD&st=commit&s=MDL-37283
- http://openwall.com/lists/oss-security/2013/01/21/1
- http://www.tinymce.com/develop/changelog/?type=phpspell
- http://www.tinymce.com/forum/viewtopic.php?id=30036
- https://github.com/tinymce/tinymce_spellchecker_php/commit/22910187bfb9edae90c26e10100d8145b505b974
- https://moodle.org/mod/forum/discuss.php?d=220157



