|
AreaEdit contains a flaw that may allow a malicious user to execute arbitrary code on the web server. The issue is triggered when the SpellChecker plugin, aspell_setup.php does not properly sanitize user input to the 'lang' variable. It is possible that the flaw may allow arbitrary code execution resulting in a loss of confidentiality, integrity, and/or availability.
|