CVE-2012-6112
Estado: ModificadaMedia (5)—
classes/GoogleSpell.php in the PHP Spellchecker (aka Google Spellchecker) addon before 2.0.6.1 for TinyMCE, as used in Moodle 2.1.x before 2.1.10, 2.2.x before 2.2.7, 2.3.x before 2.3.4, and 2.4.x before 2.4.1 and other products, does not properly handle control characters, which allows remote attackers to trigger arbitrary outbound HTTP requests via a crafted string.
CVSS
- Versión: 2.0
- Vector: AV:N/AC:L/Au:N/C:N/I:P/A:N
- Puntuación base: 5
Probabilidad de explotación (EPSS)
- Probabilidad de explotación en los próximos 30 días: 2.29%
- Percentil entre todas las CVEs puntuadas: 83
- Fecha de la puntuación: 3/10/2026
EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).
Tecnologías afectadas (2)
CWE
- CWE-264
Referencias
- http://git.moodle.org/gw?p=moodle.git&a=search&h=HEAD&st=commit&s=MDL-37283
- http://openwall.com/lists/oss-security/2013/01/21/1
- http://www.tinymce.com/develop/changelog/?type=phpspell
- http://www.tinymce.com/forum/viewtopic.php?id=30036
- https://github.com/tinymce/tinymce_spellchecker_php/commit/22910187bfb9edae90c26e10100d8145b505b974
- https://moodle.org/mod/forum/discuss.php?d=220157
- http://git.moodle.org/gw?p=moodle.git&a=search&h=HEAD&st=commit&s=MDL-37283
- http://openwall.com/lists/oss-security/2013/01/21/1
- http://www.tinymce.com/develop/changelog/?type=phpspell
- http://www.tinymce.com/forum/viewtopic.php?id=30036
- https://github.com/tinymce/tinymce_spellchecker_php/commit/22910187bfb9edae90c26e10100d8145b505b974
- https://moodle.org/mod/forum/discuss.php?d=220157
JSON original (NVD)
Mostrar
{
"id": "CVE-2012-6112",
"cveTags": [],
"metrics": {
"cvssMetricV2": [
{
"type": "Primary",
"source": "nvd@nist.gov",
"cvssData": {
"version": "2.0",
"baseScore": 5,
"accessVector": "NETWORK",
"vectorString": "AV:N/AC:L/Au:N/C:N/I:P/A:N",
"authentication": "NONE",
"integrityImpact": "PARTIAL",
"accessComplexity": "LOW",
"availabilityImpact": "NONE",
"confidentialityImpact": "NONE"
},
"acInsufInfo": false,
"impactScore": 2.9,
"baseSeverity": "MEDIUM",
"obtainAllPrivilege": false,
"exploitabilityScore": 10,
"obtainUserPrivilege": false,
"obtainOtherPrivilege": false,
"userInteractionRequired": false
}
]
},
"affected": [
{
"source": "secalert@redhat.com",
"affectedData": [
{
"vendor": "n/a",
"product": "n/a",
"versions": [
{
"status": "affected",
"version": "n/a"
}
]
}
]
}
],
"published": "2013-01-27T22:55:04.320",
"references": [
{
"url": "http://git.moodle.org/gw?p=moodle.git&a=search&h=HEAD&st=commit&s=MDL-37283",
"source": "secalert@redhat.com"
},
{
"url": "http://openwall.com/lists/oss-security/2013/01/21/1",
"source": "secalert@redhat.com"
},
{
"url": "http://www.tinymce.com/develop/changelog/?type=phpspell",
"source": "secalert@redhat.com"
},
{
"url": "http://www.tinymce.com/forum/viewtopic.php?id=30036",
"tags": [
"Vendor Advisory"
],
"source": "secalert@redhat.com"
},
{
"url": "https://github.com/tinymce/tinymce_spellchecker_php/commit/22910187bfb9edae90c26e10100d8145b505b974",
"source": "secalert@redhat.com"
},
{
"url": "https://moodle.org/mod/forum/discuss.php?d=220157",
"source": "secalert@redhat.com"
},
{
"url": "http://git.moodle.org/gw?p=moodle.git&a=search&h=HEAD&st=commit&s=MDL-37283",
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "http://openwall.com/lists/oss-security/2013/01/21/1",
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "http://www.tinymce.com/develop/changelog/?type=phpspell",
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "http://www.tinymce.com/forum/viewtopic.php?id=30036",
"tags": [
"Vendor Advisory"
],
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "https://github.com/tinymce/tinymce_spellchecker_php/commit/22910187bfb9edae90c26e10100d8145b505b974",
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "https://moodle.org/mod/forum/discuss.php?d=220157",
"source": "af854a3a-2127-422b-91ae-364da2661108"
}
],
"vulnStatus": "Modified",
"weaknesses": [
{
"type": "Primary",
"source": "nvd@nist.gov",
"description": [
{
"lang": "en",
"value": "CWE-264"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "classes/GoogleSpell.php in the PHP Spellchecker (aka Google Spellchecker) addon before 2.0.6.1 for TinyMCE, as used in Moodle 2.1.x before 2.1.10, 2.2.x before 2.2.7, 2.3.x before 2.3.4, and 2.4.x before 2.4.1 and other products, does not properly handle control characters, which allows remote attackers to trigger arbitrary outbound HTTP requests via a crafted string."
},
{
"lang": "es",
"value": "classes/GoogleSpell.php en PHP Spellchecker (también conocido como Google Spellchecker) complemento anterior a v2.0.6.1 para TinyMCE, también usado en Moodle v2.1.x anterior a v2.1.10, v2.2.x anterior a v2.2.7, v2.3.x anterior a v2.3.4, y 2.4.x anterior a v2.4.1 y otros productos, no maneja adecuadamente los caracteres de control, lo que permite a atacantes remotos ejecutar peticiones arbitrarias HTTP fuera de límite, a través de cadenas modificadas."
}
],
"lastModified": "2026-06-16T23:47:50.920",
"configurations": [
{
"nodes": [
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:a:tinymce:spellchecker_php:2.0:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "6163C806-B28B-4773-BF84-53788BD113B2"
},
{
"criteria": "cpe:2.3:a:tinymce:spellchecker_php:2.0:a1:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "E81966C7-D128-4CFD-9A52-520D161779C7"
},
{
"criteria": "cpe:2.3:a:tinymce:spellchecker_php:2.0:a2:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "0273780B-6A60-41C5-BBDC-7094D83042D6"
},
{
"criteria": "cpe:2.3:a:tinymce:spellchecker_php:2.0:b1:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "51351EF6-F5C0-48C6-B81C-EA68EB2AB985"
},
{
"criteria": "cpe:2.3:a:tinymce:spellchecker_php:2.0:b2:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "EE7F0375-A2D8-4F04-B5CE-DDEA09EC380A"
},
{
"criteria": "cpe:2.3:a:tinymce:spellchecker_php:2.0:b3:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "30DE507D-CDD1-40F2-870A-DC36C4A10CBD"
},
{
"criteria": "cpe:2.3:a:tinymce:spellchecker_php:2.0:rc1:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "D919FBFE-DFCB-4A3D-A8E7-F1E79821808D"
},
{
"criteria": "cpe:2.3:a:tinymce:spellchecker_php:2.0.1:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "EB502999-18F3-48FA-B01F-2A9C75573E89"
},
{
"criteria": "cpe:2.3:a:tinymce:spellchecker_php:2.0.2:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "35637126-0FE9-4916-8BFE-545618AD542C"
},
{
"criteria": "cpe:2.3:a:tinymce:spellchecker_php:2.0.3:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "B1C08902-9E25-40FF-8D2D-A61E39E97F6A"
},
{
"criteria": "cpe:2.3:a:tinymce:spellchecker_php:2.0.6:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "5DE98361-6EE0-44DB-8D29-29CEEAF59FFB"
}
],
"operator": "OR"
}
]
},
{
"nodes": [
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:a:moodle:moodle:2.1.0:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "18C6F348-DAE9-4440-8B3A-8D92ADC6606F"
},
{
"criteria": "cpe:2.3:a:moodle:moodle:2.1.1:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "367537BF-CBDF-4CBB-91B4-6E5A567EF605"
},
{
"criteria": "cpe:2.3:a:moodle:moodle:2.1.2:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "DABBF325-C48A-4838-AC5D-0565C78976CD"
},
{
"criteria": "cpe:2.3:a:moodle:moodle:2.1.3:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "02B72177-DFB0-4242-9ED6-068E5751579B"
},
{
"criteria": "cpe:2.3:a:moodle:moodle:2.1.4:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "7226EE65-CC9F-4FDA-9791-3C8047D5C04C"
},
{
"criteria": "cpe:2.3:a:moodle:moodle:2.1.5:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "FDC55ECE-8185-4FC0-A4C9-14AABD136650"
},
{
"criteria": "cpe:2.3:a:moodle:moodle:2.1.6:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "ADFDE1FC-992E-4610-A62D-282B448402AB"
},
{
"criteria": "cpe:2.3:a:moodle:moodle:2.1.7:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "8E8EA8F6-D689-4726-9B02-0C555EFF56AB"
},
{
"criteria": "cpe:2.3:a:moodle:moodle:2.1.8:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "633480C9-D415-4BF9-9185-547EAB7ADBE2"
},
{
"criteria": "cpe:2.3:a:moodle:moodle:2.1.9:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "D4994E7C-196E-4EDC-B192-836AB3C8731B"
}
],
"operator": "OR"
}
]
},
{
"nodes": [
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:a:moodle:moodle:2.2.0:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "15A73CE2-73DA-4274-89E0-DD9A413ED17F"
},
{
"criteria": "cpe:2.3:a:moodle:moodle:2.2.1:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "39075F6E-2925-4897-B1DE-C86A066DF54B"
},
{
"criteria": "cpe:2.3:a:moodle:moodle:2.2.2:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "179DBC2B-B35F-4A19-B522-DF996D5E13E4"
},
{
"criteria": "cpe:2.3:a:moodle:moodle:2.2.3:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "FA527724-B44E-46B6-BA53-A83B012EA376"
},
{
"criteria": "cpe:2.3:a:moodle:moodle:2.2.4:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "31A8CAEA-CCCF-4678-B61E-0FFE439890DB"
},
{
"criteria": "cpe:2.3:a:moodle:moodle:2.2.5:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "3C22E1EB-57DA-4E3C-BF38-29E2F50AEBF2"
},
{
"criteria": "cpe:2.3:a:moodle:moodle:2.2.6:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "25F99A03-DD94-4380-8E6B-C95D3A57D6EF"
}
],
"operator": "OR"
}
]
},
{
"nodes": [
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:a:moodle:moodle:2.3.0:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "BFD575CF-2AF2-443F-841D-F7E25FBD455A"
},
{
"criteria": "cpe:2.3:a:moodle:moodle:2.3.1:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "AC2A1954-E30F-40EC-BA59-40D29573E7D6"
},
{
"criteria": "cpe:2.3:a:moodle:moodle:2.3.2:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "25EA194F-BE9D-49A8-AA35-FC7810C06643"
},
{
"criteria": "cpe:2.3:a:moodle:moodle:2.3.3:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "2C3888D8-8219-4DE4-8E6C-84F58AFD3B15"
}
],
"operator": "OR"
}
]
},
{
"nodes": [
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:a:moodle:moodle:2.4.0:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "B8E52813-E056-4A5C-8BF5-4DD5EF5BF041"
}
],
"operator": "OR"
}
]
}
],
"sourceIdentifier": "secalert@redhat.com"
}