aspell_setup.php in the SpellChecker plugin in DTLink AreaEdit before 0.4.3 allows remote attackers to execute arbitrary commands via shell metacharacters in the dictionary parameter (aka the lang variable).
Exploit prediction scoring system (EPSS) score
EPSS Score 0.01
EPSS Ranking 75.9%