Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2024-40269 | MEGABOT is a fully customized Discord bot for learning and fun. The `/math` command and functionality of MEGABOT versions < 1.5.0 contains a remote code execution vulnerability due to a Python `eval()`. The vulnerability allows an attacker to inject Python code into the `expression` parameter when using `/math` in any Discord channel. This vulnerability impacts any discord guild utilizing MEGABOT. This vulnerability was fixed in release version 1.5.0. |
Mon, 26 Aug 2024 18:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Weaknesses | CWE-94 |
Tue, 20 Aug 2024 21:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Megacord
Megacord megabot |
|
| CPEs | cpe:2.3:a:megacord:megabot:*:*:*:*:*:*:*:* | |
| Vendors & Products |
Megacord
Megacord megabot |
|
| Metrics |
ssvc
|
Tue, 20 Aug 2024 15:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | MEGABOT is a fully customized Discord bot for learning and fun. The `/math` command and functionality of MEGABOT versions < 1.5.0 contains a remote code execution vulnerability due to a Python `eval()`. The vulnerability allows an attacker to inject Python code into the `expression` parameter when using `/math` in any Discord channel. This vulnerability impacts any discord guild utilizing MEGABOT. This vulnerability was fixed in release version 1.5.0. | |
| Title | Remote Code Execution Vulnerability in MEGABOT | |
| Weaknesses | CWE-95 | |
| References |
|
|
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: GitHub_M
Published:
Updated: 2024-08-20T20:29:22.818Z
Reserved: 2024-08-12T18:02:04.966Z
Link: CVE-2024-43404
Updated: 2024-08-20T20:29:13.415Z
Status : Analyzed
Published: 2024-08-20T15:15:23.867
Modified: 2024-08-26T18:29:15.190
Link: CVE-2024-43404
No data.
OpenCVE Enrichment
No data.
EUVD