Eval injection in Supybot/Limnoria
Critical severity
GitHub Reviewed
Published
Nov 20, 2019
to the GitHub Advisory Database
•
Updated Sep 30, 2024
Description
Reviewed
Nov 18, 2019
Published to the GitHub Advisory Database
Nov 20, 2019
Last updated
Sep 30, 2024
Eval injection in the Math plugin of Limnoria (before 2019.11.09) and Supybot (through 2018-05-09) allows remote unprivileged attackers to disclose information or possibly have unspecified other impact via the calc and icalc IRC commands.
References