CVE-2019-19010

moderate-risk
Published 2019-11-16

Eval injection in the Math plugin of Limnoria (before 2019.11.09) and Supybot (through 2018-05-09) allows remote unprivileged attackers to disclose information or possibly have unspecified other impact via the calc and icalc IRC commands.

Do I need to act?

-
0.54% chance of exploitation
EPSS score — low exploit probability
-
Not on CISA KEV list
No confirmed active exploitation reported to CISA
+
Fix available
Upgrade to: 2dddfefa98b44b8d539455e73910cd689abb5218, 3848ae78de45b35c029cc333963d436b9d2f0a35
9
CVSS 9.8/10 Critical
NETWORK / LOW complexity

Affected Products (4)

Limnoria

Affected Vendors

44
/ 100
moderate-risk
Severity 32/34 · Critical
Exploitability 2/34 · Minimal
Exposure 10/34 · Low