Home
Trends
Vulnerabilities
News
Researchers
Why dbugs?

Nicpwns

#25334of 53,635
9.8Total CVSS
Vulnerabilities · 1
PT-2024-30562
9.8
2024-08-20
Megabot · Megabot · CVE-2024-43404
**Name of the Vulnerable Software and Affected Versions** MEGABOT versions prior to 1.5.0 **Description** The `/math` command in MEGABOT contains a remote code execution issue due to a Python `eval()` function. This allows an attacker to inject Python code into the `expression` parameter when using `/math` in any Discord channel, impacting any Discord guild that utilizes MEGABOT. **Recommendations** For versions prior to 1.5.0, update to version 1.5.0 to resolve the issue. As a temporary workaround, consider disabling the `/math` command until the update is applied. Restrict access to the `/math` command to minimize the risk of exploitation.