CVE-2019-19010
moderate-risk
Published 2019-11-16
Eval injection in the Math plugin of Limnoria (before 2019.11.09) and Supybot (through 2018-05-09) allows remote unprivileged attackers to disclose information or possibly have unspecified other impact via the calc and icalc IRC commands.
Do I need to act?
-
0.54% chance of exploitation
EPSS score — low exploit probability
-
Not on CISA KEV list
No confirmed active exploitation reported to CISA
+
Fix available
Upgrade to: 2dddfefa98b44b8d539455e73910cd689abb5218, 3848ae78de45b35c029cc333963d436b9d2f0a35
9
CVSS 9.8/10
Critical
NETWORK
/ LOW complexity
Affected Vendors
References (10)
44
/ 100
moderate-risk
Severity
32/34 · Critical
Exploitability
2/34 · Minimal
Exposure
10/34 · Low