216.73.216.233

CVE-2024-43404

· Published 20/08/2024 15:15 · Modified 26/08/2024 18:29

Labels: CVE-2024-43404 2024-08-20CVE-2024-43404CWE-94CWE-95[email protected]

Essential information

Published
20/08/2024 15:15
Modified
26/08/2024 18:29
Author
Creator
CVSS
9.8 CRITICAL (v3.1)
CISA KEV
No
CWE
CVSS vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

CVSS metrics

Description

MEGABOT is a fully customized Discord bot for learning and fun. The `/math` command and functionality of MEGABOT versions < 1.5.0 contains a remote code execution vulnerability due to a Python `eval()`. The vulnerability allows an attacker to inject Python code into the `expression` parameter when using `/math` in any Discord channel. This vulnerability impacts any discord guild utilizing MEGABOT. This vulnerability was fixed in release version 1.5.0.

NVD status

Status
Analyzed — CVE has been marked for Analysis. Normally once in this state the CVE will be analyzed by NVD staff within 24 hours.
Source
[email protected]
NVD
View on NVD

Affected products (CPE)

ProductCPE
megacord / megabot cpe:2.3:a:megacord:megabot:*:*:*:*:*:*:*:*

References