CVE-2012-6112: Moodle

Medium severity, CVSS 5.0. EPSS: 2.3% chance of exploitation in the next 30 days.

classes/GoogleSpell.php in the PHP Spellchecker (aka Google Spellchecker) addon before 2.0.6.1 for TinyMCE, as used in Moodle 2.1.x before 2.1.10, 2.2.x before 2.2.7, 2.3.x before 2.3.4, and 2.4.x before 2.4.1 and other products, does not properly handle control characters, which allows remote attackers to trigger arbitrary outbound HTTP requests via a crafted string.

Affected products

  • Moodle Moodle: version 2.1.0 only; version 2.1.1 only; version 2.1.2 only; version 2.1.3 only; version 2.1.4 only; version 2.1.5 only; …
  • Tinymce Spellchecker PHP: version 2.0 only; version 2.0.1 only; version 2.0.2 only; version 2.0.3 only; version 2.0.6 only

Published 2013-01-27. Last modified 2026-06-16.