PT-2024-30562 · Megabot+1 · Megabot+1

Nicpwns

·

Published

2024-08-20

·

Updated

2024-08-26

·

CVE-2024-43404

CVSS v3.1

9.8

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions MEGABOT versions prior to 1.5.0
Description The /math command in MEGABOT contains a remote code execution issue due to a Python eval() function. This allows an attacker to inject Python code into the expression parameter when using /math in any Discord channel, impacting any Discord guild that utilizes MEGABOT.
Recommendations For versions prior to 1.5.0, update to version 1.5.0 to resolve the issue. As a temporary workaround, consider disabling the /math command until the update is applied. Restrict access to the /math command to minimize the risk of exploitation.

Exploit

Fix

Code Injection

Eval Injection

Weakness Enumeration

Related Identifiers

CVE-2024-43404
GHSA-VHXP-4HWQ-W3P2

Affected Products

Discord
Megabot